CVE-2019-9074: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • GNU Binutils: version 2.32 only
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified

Published 2019-02-24. Last modified 2026-06-17.