CVE-2026-91781: GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference
A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elfx8664commonsectionindex of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutils (bfd/elf64-x86-64.c, elf_x86_64_common_section_index)to a version that resolves this vulnerability.Fixed in 2.48Patch 7322e9bc30cb282575a701c307851fd3d66fee68 - Compensating control
Because the attack needs to be performed locally, ensure untrusted local users/processes cannot execute or trigger the vulnerable binutils functionality on the affected host (e.g., restrict local access to the binutils execution environment).
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Exploitation requires local access and low privileges. The available data indicates availability impact only; it does not indicate confidentiality or integrity impact.
Which versions should be remediated?
GNU Binutils 2.47 is identified as affected. Upgrading to version 2.48 addresses the issue.
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used.
What patch can be used to verify the fix?
The patch identifier is 7322e9bc30cb282575a701c307851fd3d66fee68.