DEBIAN-CVE-2026-90804

Source
https://security-tracker.debian.org/tracker/CVE-2026-90804
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-90804.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-90804
Upstream
  • CVE-2026-90804
Published
2026-09-14T17:17:57Z
Modified
2026-09-15T05:00:26Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

References

Affected packages

Debian:12 / binutils

Package

Name
binutils
Purl
pkg:deb/debian/binutils?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.40-2
2.40.50.20230111-1
2.40.50.20230215-1
2.40.50.20230501-1
2.40.50.20230510-1
2.40.50.20230602-1
2.40.50.20230611-1
2.40.50.20230611-2
2.40.50.20230622-1
2.40.50.20230625-1
2.40.50.20230630-1
2.40.90.20230705-1
2.40.90.20230714-1
2.40.90.20230714-2
2.40.90.20230720-1
2.40.90.20230729-1
2.40.90.20230729-2
2.41-1
2.41-2
2.41-3
2.41-4
2.41-5
2.41-6
2.41-7
2.41.50.20230731-1
2.41.50.20230803-1
2.41.50.20230905-1
2.41.50.20231010-1
2.41.50.20231101-1
2.41.50.20231125-1
2.41.50.20231202-1
2.41.50.20231206-1
2.41.50.20231214-1
2.41.50.20231227-1
2.41.90.20240115-1
2.41.90.20240122-1
2.42-1
2.42-2
2.42-2+hurd.1
2.42-3
2.42-4
2.42.50.20240614-1
2.42.50.20240618-1
2.42.50.20240625-1
2.42.50.20240710-1
2.42.90.20240720-1
2.42.90.20240720-2
2.43-1
2.43-2
2.43.1-1
2.43.1-2
2.43.1-3
2.43.1-4
2.43.1-5
2.43.50.20240817-1
2.43.50.20240909-1
2.43.50.20241004-1
2.43.50.20241112-1
2.43.50.20241126-1
2.43.50.20241126-2
2.43.50.20241126-3
2.43.50.20241204-1
2.43.50.20241204-2
2.43.50.20241210-1
2.43.50.20241215-1
2.43.50.20241221-1
2.43.50.20241230-1
2.43.50.20250108-1
2.43.90.20250122-1
2.43.90.20250122-2
2.43.90.20250127-1
2.43.90.20250202-1
2.44-1
2.44-2
2.44-3
2.44.50.20250201-1
2.44.50.20250207-1
2.44.50.20250218-1
2.44.50.20250218-2
2.44.50.20250309-1
2.44.50.20250405-1
2.44.50.20250502-1
2.44.50.20250520-1
2.44.50.20250528-1
2.44.50.20250707-1
2.44.90.20250719-1
2.45-1
2.45-2
2.45-3
2.45-4
2.45-5
2.45-6
2.45-7
2.45-8
2.45.50.20250813-1
2.45.50.20250903-1
2.45.50.20251005-1
2.45.50.20251023-1
2.45.50.20251023-2
2.45.50.20251122-1
2.45.50.20251125-1
2.45.50.20251201-1
2.45.50.20251209-1
2.45.50.20260116-1
2.45.50.20260119-1
2.45.90.20260125-1
2.45.90.20260201-1
2.46-1
2.46-2
2.46-3
2.46.50.20260216-1
2.46.50.20260509-1
2.46.50.20260519-1
2.46.50.20260608-1
2.46.50.20260617-1
2.46.90.20260712-1
2.47-1
2.47-2
2.47-3
2.47-4
2.47-5
2.47-6
2.47.50.20260813-1
2.47.50.20260813-2
2.47.50.20260813-3
2.47.50.20260901-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-90804.json"

Debian:13 / binutils

Package

Name
binutils
Purl
pkg:deb/debian/binutils?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.44-3
2.44.50.20250201-1
2.44.50.20250207-1
2.44.50.20250218-1
2.44.50.20250218-2
2.44.50.20250309-1
2.44.50.20250405-1
2.44.50.20250502-1
2.44.50.20250520-1
2.44.50.20250528-1
2.44.50.20250707-1
2.44.90.20250719-1
2.45-1
2.45-2
2.45-3
2.45-4
2.45-5
2.45-6
2.45-7
2.45-8
2.45.50.20250813-1
2.45.50.20250903-1
2.45.50.20251005-1
2.45.50.20251023-1
2.45.50.20251023-2
2.45.50.20251122-1
2.45.50.20251125-1
2.45.50.20251201-1
2.45.50.20251209-1
2.45.50.20260116-1
2.45.50.20260119-1
2.45.90.20260125-1
2.45.90.20260201-1
2.46-1
2.46-2
2.46-3
2.46.50.20260216-1
2.46.50.20260509-1
2.46.50.20260519-1
2.46.50.20260608-1
2.46.50.20260617-1
2.46.90.20260712-1
2.47-1
2.47-2
2.47-3
2.47-4
2.47-5
2.47-6
2.47.50.20260813-1
2.47.50.20260813-2
2.47.50.20260813-3
2.47.50.20260901-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-90804.json"

Debian:14 / binutils

Package

Name
binutils
Purl
pkg:deb/debian/binutils?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.44-3
2.44.50.20250201-1
2.44.50.20250207-1
2.44.50.20250218-1
2.44.50.20250218-2
2.44.50.20250309-1
2.44.50.20250405-1
2.44.50.20250502-1
2.44.50.20250520-1
2.44.50.20250528-1
2.44.50.20250707-1
2.44.90.20250719-1
2.45-1
2.45-2
2.45-3
2.45-4
2.45-5
2.45-6
2.45-7
2.45-8
2.45.50.20250813-1
2.45.50.20250903-1
2.45.50.20251005-1
2.45.50.20251023-1
2.45.50.20251023-2
2.45.50.20251122-1
2.45.50.20251125-1
2.45.50.20251201-1
2.45.50.20251209-1
2.45.50.20260116-1
2.45.50.20260119-1
2.45.90.20260125-1
2.45.90.20260201-1
2.46-1
2.46-2
2.46-3
2.46.50.20260216-1
2.46.50.20260509-1
2.46.50.20260519-1
2.46.50.20260608-1
2.46.50.20260617-1
2.46.90.20260712-1
2.47-1
2.47-2
2.47-3
2.47-4
2.47-5
2.47-6
2.47.50.20260813-1
2.47.50.20260813-2
2.47.50.20260813-3
2.47.50.20260901-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-90804.json"