CVE-2019-9072

MEDIUM

GNU Binutils - Denial of Service via Excessive Memory Allocation in BFD Library

Title source: llm
STIX 2.1

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in setup_group in elf.c.

References (6)

Core 6
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=24237
Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=24232
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=89396
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190314-0003/
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K12541829
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-24

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (3)
gnu/binutils 2.32
netapp/hci_management_node
netapp/solidfire
Published Feb 24, 2019
Tracked Since Feb 18, 2026