CVE-2026-90804 Overview
CVE-2026-90804 is a heap buffer overflow vulnerability in GNU Binutils 2.47. The flaw resides in the _bfd_elf_write_section_eh_frame function within bfd/elf-eh-frame.c, part of the Eh Frame Section Handler component. Manipulation of the cie_length, fde_length, augmentation_data_size, or write_offset arguments triggers an out-of-bounds write via a negative-size memmove. Exploitation requires local access and user interaction. A public exploit exists, and the GNU project has not yet responded to the initial bug report. The vulnerability is classified under [CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer].
Critical Impact
Local attackers can trigger a heap out-of-bounds write leading to process crash (SEGV) when Binutils processes a malformed .eh_frame section in a crafted ELF file.
Affected Products
- GNU Binutils 2.47
- bfd/elf-eh-frame.c (Binary File Descriptor library, Eh Frame Section Handler)
- Downstream tools linking against affected libbfd (for example ld, objcopy, strip)
Discovery Timeline
- 2026-09-14 - CVE-2026-90804 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-90804
Vulnerability Analysis
The defect lives in _bfd_elf_write_section_eh_frame in bfd/elf-eh-frame.c at lines 2064, 2083, and 2193. This function serializes DWARF Call Frame Information (CFI) records — Common Information Entries (CIE) and Frame Description Entries (FDE) — back into an ELF .eh_frame section during linking or object rewriting. When the function processes a malformed .eh_frame, computations involving cie_length, fde_length, augmentation_data_size, and write_offset produce a negative or attacker-controlled size passed to memmove. The result is a heap out-of-bounds write and a segmentation fault. Impact is limited to the local process context, and a successful trigger corrupts heap memory rather than yielding remote access.
Root Cause
The root cause is missing bounds validation on length fields parsed from the input ELF file. When .eh_frame values are attacker-controlled, arithmetic on cie_length and fde_length underflows, yielding a size argument interpreted as a very large size_t by memmove. See the GitHub CVE Summit Analysis for the annotated trace.
Attack Vector
An attacker crafts a malicious ELF object containing a malformed .eh_frame section. When a local user runs a Binutils tool such as ld, objcopy, or strip against the object, the parser invokes _bfd_elf_write_section_eh_frame and triggers the negative-size memmove. Exploitation is local, requires user interaction to open the crafted file, and executes with the privileges of the invoking user. The public proof-of-concept demonstrates a reproducible SEGV. Refer to the Sourceware Bug Report #34445 for reproduction details.
Detection Methods for CVE-2026-90804
Indicators of Compromise
- Unexpected SIGSEGV crashes in ld, objcopy, strip, or other tools linking libbfd when processing untrusted object files.
- Core dumps referencing _bfd_elf_write_section_eh_frame in the stack trace.
- ELF inputs from untrusted sources containing anomalous .eh_frame CIE or FDE length fields.
Detection Strategies
- Scan build pipelines and package repositories for GNU Binutils version 2.47 using inventory tooling.
- Fuzz Binutils entry points with malformed ELF corpora, using AddressSanitizer to catch out-of-bounds writes early.
- Monitor CI/CD job logs for abnormal termination of Binutils processes during link or object manipulation steps.
Monitoring Recommendations
- Alert on SIGSEGV events from libbfd-linked binaries on developer workstations and build servers.
- Log invocations of ld, objcopy, and strip against untrusted ELF files entering the build environment.
- Track filesystem writes of ELF objects from untrusted sources into directories consumed by Binutils.
How to Mitigate CVE-2026-90804
Immediate Actions Required
- Restrict Binutils execution on shared systems to trusted ELF inputs only.
- Isolate build pipelines that process third-party object files in sandboxed or containerized environments.
- Track the Sourceware Bug Report #34445 for upstream fix status.
Patch Information
No official patch has been released. The GNU project was notified through the bug report but has not yet responded. Monitor the Sourceware Bugzilla entry and the VulDB CVE-2026-90804 record for patch availability. Downgrading to an earlier Binutils release not affected by the regression may be considered if compatibility allows.
Workarounds
- Avoid running Binutils tools directly against ELF files received from untrusted sources.
- Validate ELF inputs with a hardened parser before invoking Binutils in automated pipelines.
- Run build tooling under a non-privileged user account inside a container with restricted filesystem access.
# Run Binutils inside an ephemeral, non-privileged container for untrusted ELF inputs
docker run --rm --read-only --user 1000:1000 \
--cap-drop=ALL --security-opt=no-new-privileges \
-v "$PWD/untrusted:/work:ro" \
debian:stable-slim \
sh -c 'objdump -h /work/input.o >/dev/null'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.