Junglewise Threat Intelligence

CVE-2026-90828: GNU Binutils null pointer dereference in ELF orphan section handler

CVE-2026-90828 · Severity: medium · CVSS 5.3 · Published 2026-09-14

Technologies: Gnu Binutils. Vendors: Gnu.

Executive brief

GNU Binutils is a collection of tools used by software developers and compiler toolchains to manipulate binary files. A null pointer dereference vulnerability in the ELF orphan section handler can crash the linker when processing malformed object files during relocatable linking, potentially disrupting the build process and enabling denial-of-service attacks against build infrastructure.

Technical details

The vulnerability is a null pointer dereference in the elf_orphan_compatible() function in ld/ldelf.c (line 2092). It occurs during relocatable linking (-r flag) when processing malformed input sections that become orphans without a compatible output section. The function dereferences a NULL linked_to pointer without sanity-checking it first, assuming that the SHF_LINK_ORDER flag guarantees the pointer is valid. The attack is local and triggered by providing a crafted object file as input to the linker. An attacker can cause a segmentation fault and crash the linker process. The fix, committed by Alan Modra on 2026-09-22, adds a NULL pointer check before dereferencing the linked_to field.

Affected products

  • GNU Binutils 2.47, earlier versions back to at least 2.41

Timeline

  • 2026-07-28: disclosed: Reported to Sourceware Bugzilla as bug #34450
  • 2026-09-14: advisory: CVE-2026-90828 published
  • 2026-09-22: patched: Fix committed to master branch for Binutils 2.48 by Alan Modra

References

Related threats