Vulnerability Description
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | >= 2.35, < 2.35.2 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1943533Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e3
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8
- https://security.gentoo.org/glsa/202208-30Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=26929ExploitIssue TrackingPatch
- https://sourceware.org/git/?p=binutils-gdb.git%3Ba=patch%3Bh=372dd157272e0674d13
- https://bugzilla.redhat.com/show_bug.cgi?id=1943533Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e3
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8
- https://security.gentoo.org/glsa/202208-30Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=26929ExploitIssue TrackingPatch
- https://sourceware.org/git/?p=binutils-gdb.git%3Ba=patch%3Bh=372dd157272e0674d13
FAQ
What is CVE-2021-20294?
CVE-2021-20294 is a vulnerability with a CVSS score of 7.8 (HIGH). A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbit...
How severe is CVE-2021-20294?
CVE-2021-20294 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20294?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.