Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
Published Mar 15, 2026
7.1
HIGHCVSS 3.1
EPSS 0.19%
Description
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | affected |
- n/a
- 4.0
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Hardened Images
binutils-main-2.45.1-5.1.hum1
Fixed · RHSA-2026:33527
Red Hat Hardened Images
binutils-main-2.46.1-1.hum1
Fixed · RHSA-2026:39022
Red Hat Enterprise Linux 10
binutils
Not affected
Red Hat Enterprise Linux 10
gcc-toolset-15-binutils
Not affected
Red Hat Enterprise Linux 10
gdb
Not affected
Red Hat Enterprise Linux 10
mingw-binutils
Not affected
Red Hat Enterprise Linux 6
binutils
Affected
Red Hat Enterprise Linux 7
binutils
Not affected
Red Hat Enterprise Linux 7
gdb
Not affected
Red Hat Enterprise Linux 8
binutils
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-14-binutils
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-14-gdb
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-15-binutils
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-15-gdb
Not affected
Red Hat Enterprise Linux 8
gdb
Not affected
Red Hat Enterprise Linux 8
mingw-binutils
Not affected
Red Hat Enterprise Linux 9
binutils
Not affected
Red Hat Enterprise Linux 9
gcc-toolset-14-binutils
Not affected
Red Hat Enterprise Linux 9
gcc-toolset-15-binutils
Not affected
Red Hat Enterprise Linux 9
gdb
Not affected
Red Hat Enterprise Linux 9
mingw-binutils
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | binutils-main-2.45.1-5.1.hum1 | Fixed | RHSA-2026:33527 |
| Red Hat Hardened Images | binutils-main-2.46.1-1.hum1 | Fixed | RHSA-2026:39022 |
| Red Hat Enterprise Linux 10 | binutils | Not affected | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 10 | gdb | Not affected | n/a |
| Red Hat Enterprise Linux 10 | mingw-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 6 | binutils | Affected | n/a |
| Red Hat Enterprise Linux 7 | binutils | Not affected | n/a |
| Red Hat Enterprise Linux 7 | gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | binutils | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | binutils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-14-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-15-binutils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gdb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This MODERATE flaw in GNU Binutils (bfd linker) requires an attacker to trick a user into running the `ld` linker against a specially crafted malicious XCOFF object file. This could lead to an out-of-bounds read.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/errata/RHSA-2026:33527 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39022 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-3442 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2443828 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-12196 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3442
- https://www.cve.org/CVERecord?id=CVE-2026-3442
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:33527 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:39022 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-3442 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443828 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-12196 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3442 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-3442 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data