Debian Binutils vulnerabilities
259 known vulnerabilities affecting debian/binutils.
Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193
Vulnerabilities
Page 1 of 13
CVE-2016-2226P3LOWCVSS 7.8PoCfixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-2226 [HIGH] CVE-2016-2226: binutils - Integer overflow in the string_appends function in cplus-dem.c in libiberty allo...
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.
debian
CVE-2017-9746P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9746 [HIGH] CVE-2017-9746: binutils - The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote a...
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of rae insns printing for this file during "objdump -D" execution.
Scope: local
bookworm: resolved (fixed in 2.
debian
CVE-2017-9750P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9750 [HIGH] CVE-2017-9750: binutils - opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale...
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
Scope: local
bookworm: resolved (fixe
debian
CVE-2017-9756P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9756 [HIGH] CVE-2017-9756: binutils - The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2...
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
Scope: local
bookworm: resolved (fixed in 2.29-1
debian
CVE-2017-9742P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9742 [HIGH] CVE-2017-9742: binutils - The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows r...
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
Scope: local
bookworm: resolved (fixed in 2.29-1)
bullseye:
debian
CVE-2006-2362P3LOWCVSS 7.3PoCfixed in binutils 2.17-1 (bookworm)2006
CVE-2006-2362 [HIGH] CVE-2006-2362: binutils - Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU ...
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal
debian
CVE-2005-4807P3LOWCVSS 7.5PoCfixed in binutils 2.17-1 (bookworm)2005
CVE-2005-4807 [HIGH] CVE-2005-4807: binutils - Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (...
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Scope: local
bookworm: resolved (fixed in 2.17-1)
bullseye: resolved (fixed in 2.17-1)
forky: resolved (fixed in 2.17-1)
sid:
debian
CVE-2017-9749P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9749 [HIGH] CVE-2017-9749: binutils - The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attack...
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
Scope: local
bookworm: resolved (fixed in 2.29-1)
bullseye: resolved (fi
debian
CVE-2018-6323P3HIGHCVSS 7.8PoCfixed in binutils 2.30-3 (bookworm)2018
CVE-2018-6323 [HIGH] CVE-2018-6323: binutils - The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) libra...
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bo
debian
CVE-2017-9748P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9748 [HIGH] CVE-2017-9748: binutils - The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) lib...
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" ex
debian
CVE-2017-9747P3LOWCVSS 7.8PoCfixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9747 [HIGH] CVE-2017-9747: binutils - The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) li...
The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" e
debian
CVE-2017-14939P4LOWCVSS 5.5PoCfixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14939 [MEDIUM] CVE-2017-14939: binutils - decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka li...
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.
Scope: local
bookworm: resolved (fixed in 2.29.90
debian
CVE-2014-9939P3CRITICALCVSS 9.8fixed in binutils 2.25.90.20151125-1 (bookworm)2014
CVE-2014-9939 [CRITICAL] CVE-2014-9939: binutils - ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printin...
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
Scope: local
bookworm: resolved (fixed in 2.25.90.20151125-1)
bullseye: resolved (fixed in 2.25.90.20151125-1)
forky: resolved (fixed in 2.25.90.20151125-1)
sid: resolved (fixed in 2.25.90.20151125-1)
trixie: resolved (fixed in 2.25.90.20151125-1)
debian
CVE-2021-20294P3LOWCVSS 7.8fixed in binutils 2.35.2-1 (bookworm)2021
CVE-2021-20294 [HIGH] CVE-2021-20294: binutils - A flaw was found in binutils readelf 2.35 program. An attacker who is able to co...
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
Scope: local
bookworm: resolved (fixed in 2.35.
debian
CVE-2014-8485P3HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8485 [HIGH] CVE-2014-8485: binutils - The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier...
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24
debian
CVE-2025-11083P3LOWCVSS 4.8fixed in binutils 2.46-1 (forky)2025
CVE-2025-11083 [MEDIUM] CVE-2025-11083: binutils - A vulnerability has been found in GNU Binutils 2.45. The affected element is the...
A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946
debian
CVE-2025-11082P3LOWCVSS 4.8fixed in binutils 2.46-1 (forky)2025
CVE-2025-11082 [MEDIUM] CVE-2025-11082: binutils - A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_pa...
A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca
debian
CVE-2025-0840P3LOWCVSS 6.3fixed in binutils 2.43.90.20250122-1 (forky)2025
CVE-2025-0840 [MEDIUM] CVE-2025-0840: binutils - A vulnerability, which was classified as problematic, was found in GNU Binutils ...
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be
debian
CVE-2025-7545P3LOWCVSS 4.8fixed in binutils 2.45-3 (forky)2025
CVE-2025-7545 [MEDIUM] CVE-2025-7545: binutils - A vulnerability classified as problematic was found in GNU Binutils 2.45. Affect...
A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1
debian
CVE-2025-5244P3LOWCVSS 4.8fixed in binutils 2.45-3 (forky)2025
CVE-2025-5244 [MEDIUM] CVE-2025-5244: binutils - A vulnerability was found in GNU Binutils up to 2.44. It has been rated as criti...
A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to
debian
1 / 13Next →