CVE-2018-12697: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5% chance of exploitation in the next 30 days.

A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.

Affected products

  • Canonical Ubuntu Linux: version 16.04.4 only
  • GNU Binutils: version 2.30 only

Published 2018-06-23. Last modified 2026-06-17.