GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c. https://nvd.nist.gov/vuln/detail/CVE-2017-9039