CVE-2018-20002: F5 Traffix Signaling Delivery Controller

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.

Affected products

  • F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0; version 4.4.0 only
  • GNU Binutils: version 2.31 only
  • Netapp Vasa Provider: from 7.2

Published 2018-12-10. Last modified 2026-06-17.