Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published Apr 22, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.15%
Description
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| Red Hat | Red Hat Hardened Images | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- n/a
- n/a
- 4.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
binutils
Fix deferred
Red Hat Enterprise Linux 10
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 10
gdb
Fix deferred
Red Hat Enterprise Linux 10
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 7
binutils
Fix deferred
Red Hat Enterprise Linux 8
binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-gdb
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-gdb
Fix deferred
Red Hat Enterprise Linux 8
gdb
Fix deferred
Red Hat Enterprise Linux 8
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 9
gdb
Fix deferred
Red Hat Enterprise Linux 9
mingw-binutils
Fix deferred
Red Hat Hardened Images
binutils
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Fix deferred | n/a |
| Red Hat Hardened Images | binutils | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this vulnerability, users should avoid using the `readelf` utility on untrusted or suspicious ELF files. Processing a specially crafted ELF file with `readelf` can lead to a denial of service.
Red Hat statement
Moderate: A denial of service vulnerability in `readelf` can be triggered by processing a crafted ELF file, leading to resource exhaustion or a null pointer dereference. This issue affects Red Hat Enterprise Linux 7, 8, 9, and 10, as well as other Red Hat products that include the binutils package. Exploitation requires a local attacker to entice a user to execute `readelf` on a malicious file.
Red Hat mitigation
To mitigate this vulnerability, users should avoid using the `readelf` utility on untrusted or suspicious ELF files. Processing a specially crafted ELF file with `readelf` can lead to a denial of service.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-6844 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460016 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24710 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6844
- https://www.cve.org/CVERecord?id=CVE-2026-6844
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6844 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460016 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24710 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6844 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6844 |
Change history (0)
No recorded changes yet.