Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91780— GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference

Quick assessment

Affected
GNU Binutils
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GNU Binutils 2.47 中发现了一个安全弱点,影响的是 文件中的 函数。攻击者通过精心构造的输入触发操作,可导致空指针解引用(null pointer dereference)。该漏洞需要本地触发,且已有公开的利用程序(exploit),可被用于实际攻击。项目维护方虽已通过漏洞报告提前获知此问题,但尚未作出响应。

CVSS 3.3 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91780

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNU Binutils 2.47 cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-91780

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91780

登录查看更多情报信息。

Proof of Concept for CVE-2026-91780 (1)

Vendor Pages for CVE-2026-91780 (1)

Other References for CVE-2026-91780 (1)

Same Patch Batch · GNU · 2026-09-15 · 5 CVEs total

CVE-2026-91752 7.5 HIGH GNU libextractor before 1.15 Stack Overflow via OLE2
CVE-2026-91779 3.3 LOW GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer derefer
CVE-2026-91781 3.3 LOW GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer deref
CVE-2026-91782 3.3 LOW GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null poi

IV. Related Vulnerabilities

V. Comments for CVE-2026-91780

No comments yet


Leave a comment