Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published Aug 12, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.15%
Description
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:
1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging
The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.
An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.
The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| Red Hat | Red Hat Hardened Images | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- n/a
- 4.0
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
binutils
Fix deferred
Red Hat Enterprise Linux 10
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 10
gcc-toolset-16-binutils
Fix deferred
Red Hat Enterprise Linux 10
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 6
binutils
Out of support scope
Red Hat Enterprise Linux 7
binutils
Fix deferred
Red Hat Enterprise Linux 8
binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 8
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-16-binutils
Fix deferred
Red Hat Enterprise Linux 9
mingw-binutils
Fix deferred
Red Hat Hardened Images
binutils
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-16-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | binutils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-16-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Fix deferred | n/a |
| Red Hat Hardened Images | binutils | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Build environments should avoid running LTO-enabled linking (ld with plugin support) against untrusted or externally-supplied object and archive files. The linker is a build-time tool, not present in production runtimes, so the realistic exposure is to CI/CD pipelines and developer workstations that build from untrusted or externally-contributed sources (supply-chain style attack). Standard hardening measures (ASLR, stack protector, FORTIFY_SOURCE, PIE) substantially reduce the likelihood of arbitrary code execution via heap manipulation, limiting the more realistic impact to a linker crash (denial of service).
Red Hat statement
This Moderate severity use-after-free flaw in binutils affects Red Hat products where the GNU linker is used with Link-Time Optimization (LTO) plugins enabled, such as in development and CI/CD environments. Exploitation requires an attacker to introduce a specially crafted object or archive file into the build process, leading primarily to a denial of service due to a linker crash. Arbitrary code execution is theoretically possible but significantly hindered by existing system hardening measures.
Red Hat mitigation
Build environments should avoid running LTO-enabled linking (ld with plugin support) against untrusted or externally-supplied object and archive files. The linker is a build-time tool, not present in production runtimes, so the realistic exposure is to CI/CD pipelines and developer workstations that build from untrusted or externally-contributed sources (supply-chain style attack). Standard hardening measures (ASLR, stack protector, FORTIFY_SOURCE, PIE) substantially reduce the likelihood of arbitrary code execution via heap manipulation, limiting the more realistic impact to a linker crash (denial of service).
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 12, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00155) | 3.97th | v5 (v2026.06.15) |
| Aug 13, 2026 | 0.12% (0.00122) | 2.31th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-19548 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507832 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-19548
- https://www.cve.org/CVERecord?id=CVE-2026-19548
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-19548 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2507832 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-19548 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-19548 |
Change history (0)
No recorded changes yet.