CVE-2020-16590: GNU Binutils

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.

Affected products

  • GNU Binutils: version 2.35 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2020-12-09. Last modified 2026-06-17.