CVE-2021-20294: Buffer Overflow
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
Other sources
allows remote attackers to cause a denial of service (stack buffer overflow) or possibly have unspecified other impacts via a crafted ELF
External Reference:
https://sourceware.org/bugzilla/showbug.cgi?id=26929
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2021-20294.
What is the affected software?
The affected software is GNU Binutils version 2.35 up to version 2.35.2.
What is the severity of CVE-2021-20294?
The severity of CVE-2021-20294 is high with a CVSS score of 7.8.
What is the impact of this vulnerability?
The highest impact of this vulnerability is to confidentiality and integrity.
How can I fix CVE-2021-20294?
It is recommended to update GNU Binutils to version 2.35.2 or apply the necessary patches provided by the vendor.