5.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package bintools
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element: 1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable. An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE. The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.
References
Affected products
Matching in nixpkgs
pkgs.binutils
Tools for manipulating binaries (linker, assembler, etc.) (wrapper script)
pkgs.bintoolsDualAs
None
-
nixos-26.05 -
- nixos-26.05-small 1010.6
pkgs.bintoolsNoLibc
Tools for manipulating binaries (linker, assembler, etc.) (wrapper script)
pkgs.binutilsNoLibc
Tools for manipulating binaries (linker, assembler, etc.) (wrapper script)
pkgs.cargo-binutils
Cargo subcommands to invoke the LLVM tools shipped with the Rust toolchain
pkgs.binutils_nogold
Tools for manipulating binaries (linker, assembler, etc.) (wrapper script)
pkgs.darwin.binutils
System binary utilities (wrapper script)
pkgs.bintools-unwrapped
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.binutils-unwrapped
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.darwin.binutilsDualAs
None
-
nixos-26.05 -
- nixos-26.05-small 1010.6
pkgs.darwin.binutilsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages.bintools
System binary utilities (wrapper script)
pkgs.binutils-unwrapped_2_38
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.llvmPackages_18.bintools
System binary utilities (wrapper script)
pkgs.llvmPackages_19.bintools
System binary utilities (wrapper script)
pkgs.llvmPackages_20.bintools
System binary utilities (wrapper script)
pkgs.llvmPackages_21.bintools
System binary utilities (wrapper script)
pkgs.llvmPackages_22.bintools
System binary utilities (wrapper script)
pkgs.llvmPackages_23.bintools
System binary utilities (wrapper script)
pkgs.darwin.binutils-unwrapped
None
pkgs.minimal-bootstrap.binutils
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.rocmPackages.llvm.bintools
System binary utilities (wrapper script)
-
nixos-unstable -
- nixos-unstable-small 22.0.0-rocm
-
nixos-26.05 -
- nixos-26.05-small 22.0.0-rocm
pkgs.llvmPackages.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.binutils-unwrapped-all-targets
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.llvmPackages_18.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages_19.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages_20.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages_21.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages_22.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.llvmPackages_23.bintoolsNoLibc
System binary utilities (wrapper script)
pkgs.darwin.binutilsDualAs-unwrapped
None
-
nixos-26.05 -
- nixos-26.05-small 1010.6
pkgs.llvmPackages.bintools-unwrapped
None
pkgs.minimal-bootstrap.binutils-static
Tools for manipulating binaries (linker, assembler, etc.)
pkgs.llvmPackages_18.bintools-unwrapped
None
pkgs.llvmPackages_19.bintools-unwrapped
None
pkgs.llvmPackages_20.bintools-unwrapped
None
pkgs.llvmPackages_21.bintools-unwrapped
None
pkgs.llvmPackages_22.bintools-unwrapped
None
pkgs.llvmPackages_23.bintools-unwrapped
None
Package maintainers
-
@Ericson2314 John Ericson <John.Ericson@Obsidian.Systems>
-
@lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
-
@newAM Alex Martens <alex@thinglab.org>
-
@Stupremee Justus K <jutus.k@protonmail.com>
-
@matthiasbeyer Matthias Beyer <mail@beyermatthias.de>
-
@reckenrode Randy Eckenrode <randy@largeandhighquality.com>
-
@alyssais Alyssa Ross <hi@alyssa.is>
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
-
@emilazy Emily <nixpkgs@emily.moe>
-
@rrbutani Rahul Butani <rrbutani+nix@gmail.com>
-
@andir Andreas Rammhold <andreas@rammhold.de>
-
@RossComputerGuy Tristan Ross <tristan.ross@midstall.com>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@peterwaller-arm Peter Waller <peter.waller@arm.com>
-
@emilytrau Emily Trau <emily+nix@downunderctf.com>
-
@Gskartwii Aleksi Hannula <ahannula4@gmail.com>
-
@siraben Siraphob Phipathananunth <bensiraphob@gmail.com>
-
@06kellyjac Jack <hello+nixpkgs@j-k.io>
-
@alejandrosame Alejandro Sánchez Medina <alejandrosanchzmedina@gmail.com>