CVE-2017-6966

MEDIUM

GNU Binutils <2.28 - Use After Free

Title source: llm

Description

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

Scores

CVSS v3 5.5
EPSS 0.0028
EPSS Percentile 50.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-416
Status draft

Affected Products (1)

gnu/binutils

Timeline

Published Mar 17, 2017
Tracked Since Feb 18, 2026