CVE-2019-17450: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
Affected products
- Canonical Ubuntu Linux: version 18.04 only
- GNU Binutils: version 2.32 only
- Opensuse Leap: version 15.1 only; version 15.2 only
Published 2019-10-10. Last modified 2026-06-17.