{"id":"CVE-2020-35507","title":"There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference","summary":"There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The grea…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"gnu","product":"binutils","affected":["binutils < 2.34","enterprise_linux = 8.0","hci_compute_node_firmware","cloud_backup","ontap_select_deploy_administration_utility","solidfire,_enterprise_sds_&_hci_storage_node","solidfire_&_hci_management_node","brocade_fabric_operating_system"],"patched":["binutils 2.34"],"published":"2021-01-04","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-35507","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911691","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1911691","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202107-24","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210212-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0125,"epssPercentile":0.68485,"ingestedAt":"2026-10-08T23:16:47.313Z","slug":"CVE-2020-35507","body":"## Overview\n\nThere's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.\n\n## Affected\n\n- `binutils < 2.34`\n- `enterprise_linux = 8.0`\n- `hci_compute_node_firmware`\n- `cloud_backup`\n- `ontap_select_deploy_administration_utility`\n- `solidfire,_enterprise_sds_&_hci_storage_node`\n- `solidfire_&_hci_management_node`\n- `brocade_fabric_operating_system`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `binutils 2.34`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}