---
id: CVE-2020-35507
title: >-
  There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in
  versions prior to 2.34 which could allow an attacker who is able to submit a
  crafted file to be processed by objdump to cause a NULL pointer dereference
summary: >-
  There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in
  versions prior to 2.34 which could allow an attacker who is able to submit a
  crafted file to be processed by objdump to cause a NULL pointer dereference.
  The grea…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: gnu
product: binutils
affected:
  - binutils < 2.34
  - enterprise_linux = 8.0
  - hci_compute_node_firmware
  - cloud_backup
  - ontap_select_deploy_administration_utility
  - 'solidfire,_enterprise_sds_&_hci_storage_node'
  - solidfire_&_hci_management_node
  - brocade_fabric_operating_system
patched:
  - binutils 2.34
published: '2021-01-04'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-35507'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1911691'
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202107-24'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20210212-0007/'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1911691'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202107-24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210212-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0125
epssPercentile: 0.68485
ingestedAt: '2026-10-08T23:16:47.313Z'
---

## Overview

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.

## Affected

- `binutils < 2.34`
- `enterprise_linux = 8.0`
- `hci_compute_node_firmware`
- `cloud_backup`
- `ontap_select_deploy_administration_utility`
- `solidfire,_enterprise_sds_&_hci_storage_node`
- `solidfire_&_hci_management_node`
- `brocade_fabric_operating_system`

## Remediation

Upgrade past the affected range:

- `binutils 2.34`
