CVE-2017-8421: High severity binutils vulnerability
Last updated 24 July 2024
Other sources
The function coffsetalignmenthook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dumprelocsinsection in objdump.c can resolve this.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-8421?
CVE-2017-8421 is a vulnerability in the Binary File Descriptor (BFD) library in GNU Binutils 2.28, which can cause memory exhaustion in objdump via a crafted PE file.
How does CVE-2017-8421 affect Binutils?
CVE-2017-8421 affects Binutils version 2.28.
How can I fix CVE-2017-8421?
To fix CVE-2017-8421, you should update Binutils to version 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Is there a patch available for CVE-2017-8421?
Yes, Binutils version 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5 include patches for CVE-2017-8421.
Where can I find more information about CVE-2017-8421?
More information about CVE-2017-8421 can be found at the following references: [https://sourceware.org/bugzilla/show_bug.cgi?id=21440](https://sourceware.org/bugzilla/show_bug.cgi?id=21440), [https://security.gentoo.org/glsa/201709-02](https://security.gentoo.org/glsa/201709-02), [https://launchpad.net/bugs/cve/CVE-2017-8421](https://launchpad.net/bugs/cve/CVE-2017-8421).