Red Hat Binutils Readelf Utility Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the readelf utility of the binutils package. This vulnerability can be exploited by a local attacker who provides a specially crafted Executable and Linkable Format (ELF) file. The exploitation leads to two issues: resource exhaustion, causing an out-of-memory condition, and a null pointer dereference, which results in a segmentation fault. Both issues can cause the readelf utility to become unresponsive or crash, thereby denying service.

Impact

Exploitation of this vulnerability causes the readelf utility to crash or become unresponsive, leading to a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by processing a crafted ELF file with the readelf utility. The malformed ELF file should be designed to trigger excessive memory allocation or cause a null pointer dereference, both of which can be achieved by manipulating specific ELF file headers or sections.

Remediation

Users are advised to avoid using the readelf utility on untrusted or suspicious ELF files.

Added: Apr 22, 2026, 11:35 AM
Updated: Apr 22, 2026, 11:35 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
5.6
remediation
7.9
relevance
6.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.