CVE-2020-16592 PUBLISHED

A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

EPSS 0.34% · 56.5th percentile

Risk Scores

EPSS Score
0.34%
56.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbinutils0, 2.29.1-4ubuntu1, 2.29.1-6ubuntu1
Ubuntu:20.04:LTSbinutils0, 2.33-2ubuntu1, 2.33.1-1ubuntu1

Timeline

References

Open in Interactive Console →