Executive brief
The GNU linker (ld), a compiler component used in build systems to combine object files into executables, contains use-after-free memory safety flaws in its plugin handling code. An attacker who can inject a crafted object file into a build process could crash the linker or potentially execute arbitrary code, disrupting software builds and potentially compromising the resulting binaries in supply-chain scenarios.
Technical details
Multiple use-after-free vulnerabilities exist in the add_archive_element function (ld/ldmain.c) of the GNU linker when LTO plugins are active. The root cause is in plugin_maybe_claim() (ld/plugin.c), which frees a BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive is NULL, but the caller retains dangling pointers to both the original abfd parameter and a shallow copy (orig_input.the_bfd). These dangling pointers are dereferenced at three locations: line ~1442 accessing abfd->my_archive, line ~1493 in conditional checks and bfd_get_filename calls, and line ~1525 in trace logging. The vulnerability is reachable when LTO plugins are enabled (confirmed in Red Hat binutils builds with --enable-plugins and --enable-lto) and triggered by standalone object files where abfd->my_archive is NULL. Attack vector is local (build-time tool) requiring attacker ability to supply crafted input files to the linker; exploitation results in denial of service via segmentation fault, with arbitrary code execution theoretically possible but substantially mitigated by stack protector, FORTIFY_SOURCE, ASLR, and PIE. No patch availability status disclosed in advisory.
Affected products
- GNU binutils <UNKNOWN>
Timeline
- 2026-08-12: disclosed