Executive brief
GNU Binutils is a collection of tools used by software developers and compiler toolchains to manipulate binary files. A null pointer dereference vulnerability in the ELF orphan section handler can crash the linker when processing malformed object files during relocatable linking, potentially disrupting the build process and enabling denial-of-service attacks against build infrastructure.
Technical details
The vulnerability is a null pointer dereference in the elf_orphan_compatible() function in ld/ldelf.c (line 2092). It occurs during relocatable linking (-r flag) when processing malformed input sections that become orphans without a compatible output section. The function dereferences a NULL linked_to pointer without sanity-checking it first, assuming that the SHF_LINK_ORDER flag guarantees the pointer is valid. The attack is local and triggered by providing a crafted object file as input to the linker. An attacker can cause a segmentation fault and crash the linker process. The fix, committed by Alan Modra on 2026-09-22, adds a NULL pointer check before dereferencing the linked_to field.
Affected products
- GNU Binutils 2.47, earlier versions back to at least 2.41
Timeline
- 2026-07-28: disclosed: Reported to Sourceware Bugzilla as bug #34450
- 2026-09-14: advisory: CVE-2026-90828 published
- 2026-09-22: patched: Fix committed to master branch for Binutils 2.48 by Alan Modra