A security flaw has been discovered in GNU Binutils 2.47. (CVE-2026-90828)
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
AI Analysis
Technical Summary
CVE-2026-90828 is a vulnerability in GNU Binutils version 2.47 involving the elf_orphan_compatible function within the ld/ldelf.c file. The flaw leads to a null pointer dereference when manipulated, potentially causing a denial of service or other impacts related to memory corruption. Exploitation requires local access with low privileges and no user interaction. The vulnerability has a CVSS 3.1 base score of 5.3, indicating medium severity. Although an exploit has been publicly released, the GNU Binutils project has not yet responded or provided a patch.
Potential Impact
The vulnerability can cause a null pointer dereference, which may lead to denial of service or other memory corruption impacts affecting confidentiality, integrity, and availability at a low level. Exploitation requires local access with low privileges, limiting the attack surface. The availability of public exploit code increases the risk of exploitation despite the lack of vendor response.
Mitigation Recommendations
No official patch or remediation has been provided by the vendor as of the current information. Users should monitor the GNU Binutils project for updates and consider restricting local access to trusted users only. Since the vulnerability requires local access, limiting user privileges and access controls can reduce risk until a fix is available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
A security flaw has been discovered in GNU Binutils 2.47. (CVE-2026-90828)
Description
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90828 is a vulnerability in GNU Binutils version 2.47 involving the elf_orphan_compatible function within the ld/ldelf.c file. The flaw leads to a null pointer dereference when manipulated, potentially causing a denial of service or other impacts related to memory corruption. Exploitation requires local access with low privileges and no user interaction. The vulnerability has a CVSS 3.1 base score of 5.3, indicating medium severity. Although an exploit has been publicly released, the GNU Binutils project has not yet responded or provided a patch.
Potential Impact
The vulnerability can cause a null pointer dereference, which may lead to denial of service or other memory corruption impacts affecting confidentiality, integrity, and availability at a low level. Exploitation requires local access with low privileges, limiting the attack surface. The availability of public exploit code increases the risk of exploitation despite the lack of vendor response.
Mitigation Recommendations
No official patch or remediation has been provided by the vendor as of the current information. Users should monitor the GNU Binutils project for updates and consider restricting local access to trusted users only. Since the vulnerability requires local access, limiting user privileges and access controls can reduce risk until a fix is available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fx9g-rhcq-63jg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90828"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6aa8a16455bf5e2cf5f3b7ad
Added to database: 09/15/2026, 01:37:40 UTC
Last enriched: 09/15/2026, 01:43:54 UTC
Last updated: 09/15/2026, 01:45:37 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.