{"id":"CVE-2020-35494","title":"There's a flaw in binutils /opcodes/tic4x-dis.c","summary":"There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-908"],"vendor":"gnu","product":"binutils","affected":["binutils < 2.34","fedora = 32","cloud_backup","ontap_select_deploy_administration_utility","solidfire,_enterprise_sds_&_hci_storage_node","solidfire_&_hci_management_node","brocade_fabric_operating_system_firmware","hci_compute_node_firmware"],"patched":["binutils 2.34"],"published":"2021-01-04","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:59.750","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-35494","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911439","label":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911439","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01087,"epssPercentile":0.6428,"ingestedAt":"2026-10-08T23:16:47.312Z","slug":"CVE-2020-35494","body":"## Overview\n\nThere's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.\n\n## Affected\n\n- `binutils < 2.34`\n- `fedora = 32`\n- `cloud_backup`\n- `ontap_select_deploy_administration_utility`\n- `solidfire,_enterprise_sds_&_hci_storage_node`\n- `solidfire_&_hci_management_node`\n- `brocade_fabric_operating_system_firmware`\n- `hci_compute_node_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `binutils 2.34`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}