CVE-2022-48063: GNU Binutils

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

Affected products

  • GNU Binutils: before 2.40 (fixed in 2.40)

Published 2023-08-22. Last modified 2026-06-17.