← Vulnerability feed

Vulnerability record · CVE-2019-9076 · published 24 February 2019

CVE-2019-9076: Gnu binutils allocation without limits vulnerability

Gnu · Binutils

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.

5.5 CVSS 3.1 Medium EPSS 1.2% · top 32.3% CWE-770 · Allocation without limits
5.5CVSS 3.1 base score, v2 4.3
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12699Gnu binutils out-of-bounds write vulnerabilityfinish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified o…EPSS 4.5%9.8CVE-2018-11236Gnu glibc integer overflow vulnerabilitystdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi…EPSS 7.1%9.8CVE-2018-6485Gnu glibc integer overflow vulnerabilityAn integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul…EPSS 4.7%9.8CVE-2017-7614Gnu binutils null pointer dereference vulnerabilityelflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" un…EPSS 3.8%9.8CVE-2014-9939Gnu binutils memory buffer overflow vulnerabilityihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.EPSS 2.3%9.1CVE-2017-7226Gnu binutils out-of-bounds read vulnerabilityThe pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-b…EPSS 2.5%9.1CVE-2017-6969Gnu binutils out-of-bounds read vulnerabilityreadelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro…EPSS 3.7%8.8CVE-2020-19726Gnu binutils uncontrolled resource consumption vulnerabilityAn issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a…EPSS 0.75%

Source: NIST National Vulnerability Database (record CVE-2019-9076), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.