Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet. | |
| Title | GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference | |
| First Time appeared |
Gnu
Gnu binutils |
|
| Weaknesses | CWE-404 CWE-476 |
|
| CPEs | cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu binutils |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T22:30:16.949Z
Reserved: 2026-09-13T19:21:30.799Z
Link: CVE-2026-90830
No data.
Status : Received
Published: 2026-09-14T23:18:59.620
Modified: 2026-09-14T23:18:59.620
Link: CVE-2026-90830
No data.
OpenCVE Enrichment
No data.
