CVE-2019-9076

MEDIUM

GNU Binutils - Denial of Service via Excessive Memory Allocation in elf_read_notes

Title source: llm
STIX 2.1

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.

References (4)

Core 4
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=24238
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190314-0003/
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K44650639
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-24

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (2)
gnu/binutils 2.32
netapp/element_software_management
Published Feb 24, 2019
Tracked Since Feb 18, 2026