CVE-2019-9076: GNU Binutils

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.

Affected products

  • GNU Binutils: version 2.32 only
  • Netapp Element Software Management: any version

Published 2019-02-24. Last modified 2026-06-17.