CVE-2026-90829: GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference
A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfdelfsetgroupcontents of the file bfd/elf.c of the component SHTGROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack must be launched locally and requires low privileges. No user interaction is required according to the supplied vector.
Is exploit code available?
Yes. The description states that a public exploit is available and could be used in attacks.
Which component is affected?
The affected code is the SHT_GROUP section handler, specifically the bfd_elf_set_group_contents function in bfd/elf.c.
Has a vendor response or fix been reported?
No response from the project is reported. The issue was reportedly disclosed through an early bug report, but the provided information does not identify a fix or mitigation.