---
id: CVE-2020-35495
title: There's a flaw in binutils /bfd/pef.c
summary: >-
  There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a
  crafted input file to be processed by the objdump program could cause a null
  pointer dereference. The greatest threat from this flaw is to application
  availabilit…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: gnu
product: binutils
affected:
  - binutils < 2.34
  - fedora = 32
  - cloud_backup
  - ontap_select_deploy_administration_utility
  - 'solidfire,_enterprise_sds_&_hci_storage_node'
  - solidfire_&_hci_management_node
  - brocade_fabric_operating_system_firmware
  - hci_compute_node_firmware
patched:
  - binutils 2.34
published: '2021-01-04'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:59.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-35495'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1911441'
    label: secalert@redhat.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202107-24'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20210212-0007/'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1911441'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KOK3QWSVOUJWJ54HVGIFWNLWQ5ZY4S6/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202107-24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210212-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0117
epssPercentile: 0.66446
ingestedAt: '2026-10-08T23:16:47.312Z'
---

## Overview

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

## Affected

- `binutils < 2.34`
- `fedora = 32`
- `cloud_backup`
- `ontap_select_deploy_administration_utility`
- `solidfire,_enterprise_sds_&_hci_storage_node`
- `solidfire_&_hci_management_node`
- `brocade_fabric_operating_system_firmware`
- `hci_compute_node_firmware`

## Remediation

Upgrade past the affected range:

- `binutils 2.34`
