CVE-2017-7227: GNU Binutils
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.
Affected products
- GNU Binutils: version 2.28 only
Published 2017-03-22. Last modified 2026-06-17.