Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

binutils — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in binutils, with AI-generated Chinese analysis, references, and POCs.

This page details the Common Weakness Enumeration (CWE) vulnerabilities associated with the binutils software product, developed by the Free Software Foundation. It aggregates security issues that affect the integrity, confidentiality, or availability of the GNU Binary Utilities suite, which is widely used for developing and debugging high-performance code. The collected data encompasses a broad spectrum of weakness types, including buffer overflows, improper input validation, and memory corruption flaws, providing a comprehensive view of the security posture of this critical development tool. The time range for these records extends from the earliest identified weaknesses in the software’s history through recent disclosures, ensuring a complete chronological overview of security regressions and fixes. By examining this aggregation, users can track vendor advisories and understand how specific weakness classes have manifested within binutils over time. The page serves as a historical record, allowing developers and security analysts to look up the vulnerability history of the product and identify trends in error-prone components. This structured approach helps in assessing risk and prioritizing patching efforts for organizations relying on GNU bin utilities for their build and analysis pipelines. Understanding these patterns supports better secure coding practices and more effective maintenance strategies for legacy and current versions of the software.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2025-0840 GNU Binutils objdump.c disassemble_bytes stack-based overflow CWE-121 5.0 Medium2025-01-29
CVE-2023-25584 Out of bounds read in parse_module function in bfd/vms-alpha.c CWE-125 6.3 Medium2023-09-14
CVE-2023-25585 Field `file_table` of `struct module *module` is uninitialized CWE-457 4.7 Medium2023-09-14
CVE-2023-25586 Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitialized CWE-457 4.7 Medium2023-09-14
CVE-2023-25588 Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab` CWE-457 4.7 Medium2023-09-14
CVE-2023-1972 GNU Binutils 缓冲区错误漏洞 CWE-119 5.5 -2023-05-17
CVE-2023-1579 GNU Binutils 缓冲区错误漏洞 CWE-119 7.8 -2023-04-03
CVE-2022-4285 Fedora 代码问题漏洞 CWE-476 5.5 -2023-01-27
CVE-2021-3530 GNU Binutils 安全漏洞 CWE-674 7.5 -2021-06-02
CVE-2021-3549 GNU Binutils 缓冲区错误漏洞 CWE-119 8.1 -2021-05-26
CVE-2021-20294 binutils readelf 缓冲区错误漏洞 CWE-787 7.8 -2021-04-29
CVE-2021-20197 GNU Binutils 后置链接漏洞 CWE-59 6.7 -2021-03-26
CVE-2021-20284 GNU Binutils 缓冲区错误漏洞 CWE-119 5.5 -2021-03-26
CVE-2020-35507 GNU Binutils 代码问题漏洞 CWE-476 5.5 -2021-01-04
CVE-2020-35496 GNU Binutils 代码问题漏洞 CWE-476 5.5 -2021-01-04
CVE-2020-35495 GNU Binutils 代码问题漏洞 CWE-476 5.5 -2021-01-04
CVE-2020-35494 GNU Binutils 安全漏洞 CWE-908 6.1 -2021-01-04
CVE-2020-35493 GNU Binutils 输入验证错误漏洞 CWE-20 5.5 -2021-01-04

All 48 known CVE vulnerabilities affecting binutils with full Chinese analysis, references, and POCs where available.