{"id":"CVE-2021-3549","details":"An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.","modified":"2026-08-28T14:32:45.552421Z","published":"2021-05-26T21:15:08.347Z","references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-30"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250228-0005/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1960717"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/binutils-gdb.git","events":[{"introduced":"9288e0fae61b716ce75334be906283de8b18b787"},{"last_affected":"9288e0fae61b716ce75334be906283de8b18b787"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:binutils:2.36:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.36"},{"last_affected":"2.36"}],"source":"CPE_STRING"}}],"versions":["2.36","binutils-2_36"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3549.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}