Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Ubuntu: (CVE-2021-3549): binutils vulnerability

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:P)
Published
May 26, 2021
Added
Nov 19, 2024
Modified
Mar 27, 2026

Description

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

Solution

ubuntu-upgrade-binutils
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.