CVE-2020-16592: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

Affected products

  • Fedoraproject Fedora: version 32 only; version 33 only
  • GNU Binutils: version 2.34 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2020-12-09. Last modified 2026-06-17.