CVE-2018-6543: GNU Binutils

High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.

In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

Affected products

  • GNU Binutils: version 2.30 only

Published 2018-02-02. Last modified 2026-06-17.