SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90802

MEDIUM · CVSS 4.4 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A null pointer dereference vulnerability exists in the bfd_putl64 function of GNU Binutils 2.47, which could be exploited by attackers with local access to the system. This weakness may lead to application crashes or denial of service, impacting the stability of affected systems. Organizations using GNU Binutils should prioritize addressing this vulnerability to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90802
Severity
MEDIUM
CVSS
4.4
EPSS
N/A

Original NVD Description

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.