CVE-2020-21490
CVE-2020-21490 is a medium-severity vulnerability in Gnu Binutils with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Gnu Binutils
- Published:
- Last modified:
Description
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
Frequently asked questions
- What is CVE-2020-21490?
- An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
- How severe is CVE-2020-21490?
- CVE-2020-21490 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2020-21490 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-21490?
- CVE-2020-21490 affects Gnu Binutils. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-21490?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-21490 published?
- CVE-2020-21490 was published on 2023-08-22 and last updated on 2026-06-17.
References
- https://security.netapp.com/advisory/ntap-20230929-0007/
- https://sourceware.org/bugzilla/show_bug.cgi?id=25249
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=378fd436405b3051df34ac995b2e03fe1f3d1907
Affected products (1)
- cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
More vulnerabilities in Gnu Binutils
- CVE-2018-12699 — Critical (CVSS 9.8): finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow)…
- CVE-2017-7614 — Critical (CVSS 9.8): elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member…
- CVE-2014-9939 — Critical (CVSS 9.8): ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
- CVE-2017-7226 — Critical (CVSS 9.1): The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils…
- CVE-2017-6969 — Critical (CVSS 9.1): readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The…
- CVE-2020-19726 — High (CVSS 8.8): An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or…
All CVEs affecting Gnu Binutils →
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →