CVE-2026-90802: GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference
A weakness has been identified in GNU Binutils 2.47. Affected is the function bfdputl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
An attacker needs local access and low-level privileges. No user interaction is required, and the attack complexity is rated low.
What impact can successful exploitation have?
The reported impact is limited to integrity and availability, both rated low. No confidentiality impact is reported.
Is a fix or vendor response available?
The provided information states that the project was notified through an early bug report but had not responded. No patch or workaround is identified in the available data.