CVE-2017-6969: GNU Binutils

Critical severity, CVSS 9.1. EPSS: 3.8% chance of exploitation in the next 30 days.

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

Affected products

  • GNU Binutils: version 2.28 only

Published 2017-03-17. Last modified 2026-06-17.