CVE-2026-91781: GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference

Published Sep 15, 2026
·
Updated

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elfx8664commonsectionindex of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.

Affected Software

1 affected component
GNU binutils<=2.47

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GNU Binutils (bfd/elf64-x86-64.c, elf_x86_64_common_section_index) to a version that resolves this vulnerability.

    Fixed in 2.48Patch 7322e9bc30cb282575a701c307851fd3d66fee68
  2. Compensating control

    Because the attack needs to be performed locally, ensure untrusted local users/processes cannot execute or trigger the vulnerable binutils functionality on the affected host (e.g., restrict local access to the binutils execution environment).

Event History

Sep 15, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to exploitation?

Exploitation requires local access and low privileges. The available data indicates availability impact only; it does not indicate confidentiality or integrity impact.

2

Which versions should be remediated?

GNU Binutils 2.47 is identified as affected. Upgrading to version 2.48 addresses the issue.

3

Is exploit code available?

Yes. The exploit has been publicly disclosed and may be used.

4

What patch can be used to verify the fix?

The patch identifier is 7322e9bc30cb282575a701c307851fd3d66fee68.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203