🛡️ ECHO-2327-9760-e268 — binutils
Description
Claimed out-of-bounds write in dlx_rtype_to_howto() (bfd/elf32-dlx.c),
reached from elf32_dlx_info_to_howto_rel() via the relocation type of a
crafted ELF/DLX object.
The DLX backend is not built. dlx_elf32_be_vec is selected only by the
dlx-*-elf target triple (bfd/config.bfd), and that vec is the sole trigger
for compiling elf32-dlx.lo (bfd/configure.ac); debian/rules passes an
explicit per-architecture --enable-targets list and never
--enable-targets=all. Verified against the shipped amd64 and arm64 debs:
libbfd exports no dlx symbols, objdump -b elf32-dlx returns "invalid bfd
target", ld -m elf32dlx is an unrecognised emulation, and a crafted
EM_DLX (0x5aa5) object carrying relocation types past the end of the howto
table is claimed by the generic elf32-big backend, which reports
"architecture: UNKNOWN!" and every relocation as UNKNOWN. The function is
never entered. Note that readelf prints DLX machine and relocation names
from its own tables, independent of BFD, so its output is not evidence of
the backend being present.
Upstream also rejects the finding on its merits, even with DLX enabled. On
the Red Hat bug that Debian's tracker carries as its only reference,
maintainer Andrew Burgess concludes "I don't believe that this is actually
a bug": DLX relocation types are a contiguous 0-9, not the non-contiguous
space with extended types at 0x10000+ that the advisory describes;
dlx_rtype_to_howto() already rejects r_type >= R_DLX_max (10); and types
6-9 have their own case arms, so the indexed access can only ever reach
0-5 of the 6-entry dlx_elf_howto_table. Patrick Monnerat adds that the
advisory claims an out-of-bounds write while the procedure performs no
indexed write at all. Both observations hold against the
2.45.50.20251201 source.
Debian marks it unimportant (binutils not covered by security support) and
ships no fix in any suite including forky/sid, so there is nothing to bump.
Affected software
ECHO-2327-9760-e268 is recorded against 1 package.
- binutils (fixed in 2.45.90.20260201+really2.45.50.20251201-1+e9)
Timeline and source
Published on 30 July 2026 and last revised on 2 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| binutils | — | 2.45.90.20260201+really2.45.50.20251201-1+e9 |
References
Similar Threats
- Unknown ALSA-2025:23306
- Unknown ALSA-2025:23343
- Unknown ALSA-2025:23382
- Unknown ALSA-2025:20155
- Unknown ALPINE-CVE-2025-8224
More ECHO 2 advisories
Browse all of ECHO 2 in the advisory index.
- ECHO-2251-f2e7-9c06
- ECHO-2259-d6c1-3019
- ECHO-2275-6171-e763
- ECHO-2283-261e-dd99
- ECHO-2289-8a59-96ae
- ECHO-2289-ed41-d73f
- ECHO-2294-4704-f018
- ECHO-2294-b00a-6417
- ECHO-2361-31e6-b714
- ECHO-2375-d1f1-479d
- ECHO-2377-cc5e-c479
- ECHO-2378-eaef-6b85
- ECHO-2387-cb23-dd37
- ECHO-2388-0f99-a7b2
- ECHO-2389-0370-77c0
- ECHO-2396-cdff-436a
Free Vulnerability Check
Is your site affected by ECHO-2327-9760-e268?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ECHO-2327-9760-e268 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.