CVE-2021-20284

MEDIUM

GNU Binutils - Out-of-Bounds Write

Title source: rule

Description

A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 24.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-119 CWE-787
Status published

Affected Products (3)

gnu/binutils
netapp/cloud_backup
netapp/ontap_select_deploy_administration_utility

Timeline

Published Mar 26, 2021
Tracked Since Feb 18, 2026