CVE-2017-16831: GNU Binutils

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file.

Affected products

  • GNU Binutils: version 2.29.1 only

Published 2017-11-15. Last modified 2026-06-17.