Junglewise Threat Intelligence

CVE-2026-3442: GNU Binutils out-of-bounds read in bfd linker

CVE-2026-3442 · Severity: medium · CVSS 6.1 · Published 2026-03-16

Technologies: Red Hat Enterprise Linux 6, Gnu Binutils. Vendors: Red Hat, Gnu.

Executive brief

A security vulnerability has been identified in GNU Binutils, a collection of programming tools used to create and manage executable files and libraries. An attacker could exploit this flaw by tricking a user into processing a specially crafted malicious file. If successful, this could allow the attacker to view sensitive information or cause the software to crash, potentially disrupting development workflows or system operations.

Technical details

A heap-based buffer overflow, specifically an out-of-bounds read, exists in the Binary File Descriptor (BFD) linker component of GNU Binutils. The flaw is located in 'bfd/xcofflink.c' within the 'xcoff_link_add_symbols' function, where the 'r_symndx' variable is used to index symbol hashes without adequate bounds checking. An attacker can exploit this by providing a specially crafted XCOFF object file to the 'ld' linker. Successful exploitation requires user interaction (processing the malicious file) and can result in information disclosure or an application-level denial of service (crash). Red Hat has released patches for affected components in Red Hat Hardened Images (e.g., binutils-2.45.1-5.1.hum1).

Affected products

  • GNU Binutils Versions prior to 2.45.1-5.1.hum1
  • Red Hat Enterprise Linux 6 Affected
  • Red Hat Hardened Images Affected

Timeline

  • 2026-03-02: disclosed: Initial report in Red Hat Bugzilla
  • 2026-03-16: advisory: NVD publication date
  • 2026-06-30: patched: Red Hat released security update RHSA-2026:33527

References

Related threats