CVE-2020-35493: Broadcom Brocade Fabric Operating System Firmware

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

Affected products

  • Broadcom Brocade Fabric Operating System Firmware: affected versions not specified
  • Fedoraproject Fedora: version 32 only
  • GNU Binutils: before 2.34 (fixed in 2.34)
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Hci Compute Node Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Solidfire, Enterprise Sds & Hci Storage Node: affected versions not specified
  • Netapp Solidfire & Hci Management Node: affected versions not specified

Published 2021-01-04. Last modified 2026-10-08.