CVE-2021-45078

HIGH

GNU Binutils < 2.37 - Out-of-Bounds Write

Title source: rule

Description

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-787
Status published

Affected Products (8)

gnu/binutils < 2.37
fedoraproject/fedora
fedoraproject/fedora
redhat/enterprise_linux
debian/debian_linux
debian/debian_linux
debian/debian_linux
netapp/ontap_select_deploy_administration_utility

Timeline

Published Dec 15, 2021
Tracked Since Feb 18, 2026