CVE-2017-6969

Updated: 2026-02-27 02:56:16.702591

Description:

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.4
CVSS Version 3.x CRITICAL 9.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS binutils 2.20 9.1 CRITICAL Not Vulnerable 2021-11-02 21:02:48 Not affected: This flaw targets readelf in GNU binutils 2.28 and is triggered in RL78-specific parsi...
CloudLinux 6 ELS binutils 2.20 9.1 CRITICAL Not Vulnerable 2021-11-02 21:02:48
Oracle Linux 6 ELS binutils 2.20 9.1 CRITICAL Not Vulnerable 2021-11-02 21:02:48 Not affected: This flaw targets readelf in GNU binutils 2.28 and is triggered in RL78-specific parsi...
Ubuntu 16.04 ELS binutils 2.26 9.1 CRITICAL Released CLSA-2021:1635459139 2021-11-02 21:02:48