CVE-2026-90828: GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elforphancompatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation must be initiated from a local position. The CVSS vector also indicates that the attacker needs low privileges and no user interaction.
Is exploit code available?
Yes. An exploit has been released publicly and may be used in attacks.
How can I identify potentially affected systems?
Review systems that have GNU Binutils 2.47 installed, particularly where local low-privileged users can manipulate inputs handled by the ELF orphan section component.