CVE-2019-9073

MEDIUM

GNU Binutils - Denial of Service via Excessive Memory Allocation in BFD Library

Title source: llm
STIX 2.1

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.

References (5)

Core 5
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=24233
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190314-0003/
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K37121474
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4336-1/
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-24

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 50.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (4)
canonical/ubuntu_linux 18.04
gnu/binutils 2.32
netapp/hci_management_node
netapp/solidfire
Published Feb 24, 2019
Tracked Since Feb 18, 2026