CVE-2026-90831 Overview
CVE-2026-90831 is a memory corruption vulnerability in GNU Binutils 2.47. The flaw resides in the _bfd_elf_strtab_delref function within bfd/elf-strtab.c, part of the Binary File Descriptor (BFD) library's ELF String Table component. An attacker with local access and low privileges can trigger memory corruption by manipulating input processed by this function. Public exploit details are available, though no active exploitation has been reported. The GNU project received a bug report but has not yet responded at the time of disclosure.
Critical Impact
Local attackers can trigger memory corruption in Binutils tools that parse ELF files, potentially affecting build systems, debuggers, and linkers that link against libbfd.
Affected Products
- GNU Binutils 2.47
- Tools linking against libbfd (for example ld, objdump, readelf, nm, strip)
- Downstream toolchains and distributions bundling the affected Binutils release
Discovery Timeline
- 2026-09-14 - CVE-2026-90831 published to the National Vulnerability Database (NVD)
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-90831
Vulnerability Analysis
The vulnerability is classified under CWE-119, covering improper restriction of operations within the bounds of a memory buffer. It affects _bfd_elf_strtab_delref, a reference-counting routine that decrements references to string table entries used during ELF processing. Improper handling of these reference operations can lead to memory corruption when Binutils parses a crafted or malformed ELF object. Because the BFD library underpins the entire Binutils suite, the issue can surface across any tool that reads ELF inputs, including linkers, disassemblers, and analysis utilities.
Root Cause
The root cause is in the reference-count management inside _bfd_elf_strtab_delref in bfd/elf-strtab.c. Manipulated input can drive the function into a state where memory bookkeeping becomes inconsistent, producing memory corruption. See the Sourceware Bugzilla Report for reproducer details.
Attack Vector
Exploitation requires local access with low privileges and no user interaction. An attacker supplies a crafted ELF file to any Binutils tool that invokes the affected code path. Typical scenarios include CI pipelines, package builds, and forensic workflows that process untrusted binaries. No network vector is present, and confidentiality, integrity, and availability impacts are limited in scope.
No verified exploit code is publicly indexed in ExploitDB. Technical reproducers are attached to the vendor bug tracker; refer to the Sourceware Bugzilla Attachment for details.
Detection Methods for CVE-2026-90831
Indicators of Compromise
- Crashes or abnormal termination of ld, objdump, readelf, or other libbfd-linked tools when processing ELF inputs
- Segmentation faults or ASan reports referencing _bfd_elf_strtab_delref or nearby symbols in bfd/elf-strtab.c
- Unexpected core dumps generated by build pipelines that ingest third-party object files
Detection Strategies
- Inventory hosts and build agents running GNU Binutils 2.47 using package manager queries such as dpkg -l binutils or rpm -q binutils
- Monitor process telemetry for repeated Binutils crashes tied to specific ELF artifacts
- Run Binutils utilities under AddressSanitizer or Valgrind in test environments to surface memory corruption on suspect inputs
Monitoring Recommendations
- Alert on core file creation for Binutils processes on developer workstations, build servers, and CI runners
- Track ingestion of untrusted ELF objects into build pipelines and correlate with subsequent tool crashes
- Review host EDR telemetry for anomalous child-process behavior spawned from linker or objdump invocations
How to Mitigate CVE-2026-90831
Immediate Actions Required
- Identify all systems running GNU Binutils 2.47, including container images, build agents, and developer laptops
- Restrict execution of Binutils tools against untrusted or attacker-controlled ELF files
- Subscribe to the Sourceware Bugzilla Report to receive fix notifications
Patch Information
No vendor patch has been published at the time of disclosure. The GNU project was notified through a bug report but has not yet responded. Monitor the GNU project site and Sourceware Bugzilla for the fix that will follow 2.47. Distributions typically backport Binutils security fixes; consult your vendor's advisory channel once available.
Workarounds
- Downgrade to a prior stable Binutils release that does not contain the regression, where operationally feasible
- Sandbox Binutils invocations that handle untrusted ELF objects using containers, seccomp profiles, or isolated build users
- Enforce integrity checks on ELF artifacts entering build systems to reduce exposure to crafted inputs
# Verify installed Binutils version and locate the affected package
ld --version | head -n1
rpm -q binutils 2>/dev/null || dpkg -l binutils 2>/dev/null
# Run untrusted ELF analysis inside an isolated container
docker run --rm --read-only --network=none \
-v "$PWD":/work:ro -w /work \
debian:stable objdump -x suspicious.o
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.