Debian Binutils vulnerabilities
259 known vulnerabilities affecting debian/binutils.
Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193
Vulnerabilities
Page 2 of 13
CVE-2017-6969P3CRITICALCVSS 9.1fixed in binutils 2.28-3 (bookworm)2017
CVE-2017-6969 [CRITICAL] CVE-2017-6969: binutils - readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read whil...
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
Scope: local
bookworm: resolved (fixed in 2.28-3)
bullseye: resolved (fixed in 2.28-3)
forky: resolved (fixed in 2.28-3)
sid: resolved (fixed in 2.28-3)
trixi
debian
CVE-2018-12699P3LOWCVSS 9.8fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-12699 [CRITICAL] CVE-2018-12699: binutils - finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial o...
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.2019
debian
CVE-2024-53589P3LOWCVSS 8.4fixed in binutils 2.44-1 (forky)2024
CVE-2024-53589 [HIGH] CVE-2024-53589: binutils - GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descri...
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.44-1)
sid: resolved (fixed in 2.44-1)
trixie: resolved (fixed in 2.44-1)
debian
CVE-2025-7546P3LOWCVSS 4.8fixed in binutils 2.45-3 (forky)2025
CVE-2025-7546 [MEDIUM] CVE-2025-7546: binutils - A vulnerability, which was classified as problematic, has been found in GNU Binu...
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch i
debian
CVE-2017-7226P3CRITICALCVSS 9.1fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7226 [CRITICAL] CVE-2017-7226: binutils - The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka li...
The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure
debian
CVE-2017-7614P3LOWCVSS 9.8fixed in binutils 2.28-4 (bookworm)2017
CVE-2017-7614 [CRITICAL] CVE-2017-7614: binutils - elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribut...
elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.
Scope: local
bookworm: re
debian
CVE-2018-12698P3LOWCVSS 7.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-12698 [HIGH] CVE-2018-12698: binutils - demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutil...
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fix
debian
CVE-2014-8504P3HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8504 [HIGH] CVE-2014-8504: binutils - Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binut...
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90
debian
CVE-2014-8503P3HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8503 [HIGH] CVE-2014-8503: binutils - Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binut...
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.
debian
CVE-2025-1179P3LOWCVSS 2.3fixed in binutils 2.44-1 (forky)2025
CVE-2025-1179 [LOW] CVE-2025-1179: binutils - A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. A...
A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been discl
debian
CVE-2025-5245P3LOWCVSS 4.8fixed in binutils 2.45-3 (forky)2025
CVE-2025-5245 [MEDIUM] CVE-2025-5245: binutils - A vulnerability classified as critical has been found in GNU Binutils up to 2.44...
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a
debian
CVE-2019-1010180P3LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-1010180 [HIGH] CVE-2019-1010180: binutils - GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory acces...
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: res
debian
CVE-2020-35342P3LOWCVSS 7.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35342 [HIGH] CVE-2020-35342: binutils - GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic...
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
Scope: local
bookworm: resolved (fixed in 2.33.50.20200107-1)
bullseye: resolved (fixed in 2.33.50.20200107-1)
forky: resolved (fixed in 2.33.50.20200107-1)
sid: resolved (fixed in 2.33.50.
debian
CVE-2021-3530P3LOWCVSS 7.5fixed in binutils 2.37.90.20220207-1 (bookworm)2021
CVE-2021-3530 [HIGH] CVE-2021-3530: binutils - A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c...
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Scope: local
bookworm: resolved (fixed in 2.37.90.20220207-1)
bullseye: open
forky: resolved (fixed in 2.37.90.20220207-1)
sid: resolved (fixed in 2.37.90.20220207-1)
debian
CVE-2018-1000876P3LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-1000876 [HIGH] CVE-2018-1000876: binutils - binutils version 2.32 and earlier contains a Integer Overflow vulnerability in o...
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fi
debian
CVE-2014-8502P3HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8502 [HIGH] CVE-2014-8502: binutils - Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in G...
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
fo
debian
CVE-2016-6131P3LOWCVSS 7.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-6131 [HIGH] CVE-2016-6131: binutils - The demangler in GNU Libiberty allows remote attackers to cause a denial of serv...
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.
debian
CVE-2019-9077P3LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9077 [HIGH] CVE-2019-9077: binutils - An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow...
An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: reso
debian
CVE-2018-12697P3LOWCVSS 7.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-12697 [HIGH] CVE-2018-12697: binutils - A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was disc...
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.
debian
CVE-2014-8501P3HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8501 [HIGH] CVE-2014-8501: binutils - The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and...
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (f
debian