CVE-2020-35496: Broadcom Brocade Fabric Operating System Firmware

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

Affected products

  • Broadcom Brocade Fabric Operating System Firmware: affected versions not specified
  • Fedoraproject Fedora: version 32 only
  • GNU Binutils: before 2.34 (fixed in 2.34)
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Hci Compute Node Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Solidfire, Enterprise Sds & Hci Storage Node: affected versions not specified
  • Netapp Solidfire & Hci Management Node: affected versions not specified

Published 2021-01-04. Last modified 2026-10-08.