CVE-2021-3530: GNU Binutils

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.

Affected products

  • GNU Binutils: version 2.36 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2021-06-02. Last modified 2026-06-17.