Junglewise Threat Intelligence

CVE-2026-19548: GNU binutils ld use-after-free in add_archive_element

CVE-2026-19548 · Severity: medium · CVSS 5.5 · Published 2026-08-12

Technologies: Gnu Binutils. Vendors: Gnu.

Executive brief

The GNU linker (ld), a compiler component used in build systems to combine object files into executables, contains use-after-free memory safety flaws in its plugin handling code. An attacker who can inject a crafted object file into a build process could crash the linker or potentially execute arbitrary code, disrupting software builds and potentially compromising the resulting binaries in supply-chain scenarios.

Technical details

Multiple use-after-free vulnerabilities exist in the add_archive_element function (ld/ldmain.c) of the GNU linker when LTO plugins are active. The root cause is in plugin_maybe_claim() (ld/plugin.c), which frees a BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive is NULL, but the caller retains dangling pointers to both the original abfd parameter and a shallow copy (orig_input.the_bfd). These dangling pointers are dereferenced at three locations: line ~1442 accessing abfd->my_archive, line ~1493 in conditional checks and bfd_get_filename calls, and line ~1525 in trace logging. The vulnerability is reachable when LTO plugins are enabled (confirmed in Red Hat binutils builds with --enable-plugins and --enable-lto) and triggered by standalone object files where abfd->my_archive is NULL. Attack vector is local (build-time tool) requiring attacker ability to supply crafted input files to the linker; exploitation results in denial of service via segmentation fault, with arbitrary code execution theoretically possible but substantially mitigated by stack protector, FORTIFY_SOURCE, ASLR, and PIE. No patch availability status disclosed in advisory.

Affected products

  • GNU binutils <UNKNOWN>

Timeline

  • 2026-08-12: disclosed

Related threats