CVE-2026-90828
Severity CVSS v4.0:
LOW
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
14/09/2026
Last modified:
21/09/2026
Description
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Impact
Base Score 4.0
1.90
Severity 4.0
LOW
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page


