Executive brief
A vulnerability exists in GNU binutils, a collection of programming tools used to create and manage binary files. By tricking a user or automated system into processing a specially crafted file, an attacker could gain full control over the system. This poses a significant risk to developer workstations, automated security scanners, and software build pipelines that handle untrusted code.
Technical details
An out-of-bounds write vulnerability exists in the dlx_rtype_to_howto() function within bfd/elf32-dlx.c of the BFD library in GNU binutils. The flaw stems from inadequate bounds checking on attacker-controlled relocation type values (ELF32_R_TYPE) before they are used to index the dlx_elf_howto_table[] array. Because the DLX relocation type space is non-contiguous, the default switch case allows arbitrary indices to reach the array access. An attacker can exploit this via a specially crafted ELF/DLX object file to perform a File Stream Oriented Programming (FSOP) attack against glibc FILE structures, leading to arbitrary code execution. This is exploitable when binutils is compiled with the DLX backend enabled (e.g., --enable-targets=all).
Affected products
- GNU binutils All versions built with DLX backend enabled
- Red Hat Red Hat Enterprise Linux 10 Affected (binutils package)
Timeline
- 2026-07-27: disclosed: Reported via Red Hat Bugzilla
- 2026-07-29: advisory: Published by NVD and Red Hat