Junglewise Threat Intelligence

CVE-2026-18220: GNU binutils out-of-bounds write in BFD DLX ELF backend

CVE-2026-18220 · Severity: high · CVSS 7.8 · Published 2026-07-29

Technologies: Red Hat Enterprise Linux 10, Gnu Binutils. Vendors: Red Hat, Gnu.

Executive brief

A vulnerability exists in GNU binutils, a collection of programming tools used to create and manage binary files. By tricking a user or automated system into processing a specially crafted file, an attacker could gain full control over the system. This poses a significant risk to developer workstations, automated security scanners, and software build pipelines that handle untrusted code.

Technical details

An out-of-bounds write vulnerability exists in the dlx_rtype_to_howto() function within bfd/elf32-dlx.c of the BFD library in GNU binutils. The flaw stems from inadequate bounds checking on attacker-controlled relocation type values (ELF32_R_TYPE) before they are used to index the dlx_elf_howto_table[] array. Because the DLX relocation type space is non-contiguous, the default switch case allows arbitrary indices to reach the array access. An attacker can exploit this via a specially crafted ELF/DLX object file to perform a File Stream Oriented Programming (FSOP) attack against glibc FILE structures, leading to arbitrary code execution. This is exploitable when binutils is compiled with the DLX backend enabled (e.g., --enable-targets=all).

Affected products

  • GNU binutils All versions built with DLX backend enabled
  • Red Hat Red Hat Enterprise Linux 10 Affected (binutils package)

Timeline

  • 2026-07-27: disclosed: Reported via Red Hat Bugzilla
  • 2026-07-29: advisory: Published by NVD and Red Hat

References

Related threats