A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Binutils | Gnu | 2.31.1 (including) | 2.31.1 (including) |
| Binutils | Ubuntu | bionic | * |
| Binutils | Ubuntu | cosmic | * |
| Binutils | Ubuntu | esm-infra/bionic | * |
| Binutils | Ubuntu | trusty | * |