Executive brief
GNU Binutils is a collection of binary tools used by developers to create and manage software programs. A security flaw in its linker component could allow an attacker to access sensitive information or cause the software to crash. To exploit this, an attacker would need to trick a user into processing a specially crafted malicious file, potentially leading to data exposure or a disruption of development workflows.
Technical details
A heap-based buffer overflow, specifically an out-of-bounds read, exists in the GNU Binutils BFD linker. The vulnerability is located in the 'xcoff_link_add_symbols' function within 'bfd/xcofflink.c'. It is caused by an improper validation check of the 'x_scnlen' value, which results in an out-of-bounds access on the 'csects' array. An attacker can exploit this by convincing a user to process a specially crafted XCOFF object file using the 'ld' linker. Successful exploitation can lead to the disclosure of sensitive memory contents or an application-level denial of service (crash). Red Hat has released updates for affected Hardened Images to address this and related vulnerabilities.
Affected products
- GNU Binutils 2.45.1-5.1.hum1
- Red Hat Enterprise Linux 6 affected
- Red Hat Hardened Images affected
Timeline
- 2026-03-02: disclosed: Initial report in Red Hat Bugzilla
- 2026-03-16: advisory: NVD publication date
- 2026-06-30: patched: Red Hat released security update RHSA-2026:33527