Junglewise Threat Intelligence

CVE-2026-4647: GNU Binutils BFD library out-of-bounds read in XCOFF relocation processing

CVE-2026-4647 · Severity: medium · CVSS 6.1 · Published 2026-03-23

Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Gnu Binutils, Red Hat Enterprise Linux 10. Vendors: Red Hat, Gnu.

Executive brief

A vulnerability exists in the GNU Binutils BFD library, a fundamental component used by developers and system administrators to manage and process binary files like programs and libraries. By tricking a user into opening a specially crafted XCOFF object file with an affected tool (such as a linker or debugger), an attacker can cause the application to crash or potentially reveal sensitive information from the system's memory. This could disrupt development workflows or lead to limited data exposure on affected Linux systems.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the BFD library of GNU Binutils within the xcoff_ppc_relocate_section() and xcoff64_ppc_relocate_section() functions in coff-rs6000.c and coff64-rs6000.c. The flaw is caused by improper validation of the relocation type field (r_type) read from XCOFF input files; this 8-bit value is used as an array index into howto tables (e.g., xcoff64_howto_table) before bounds checking occurs. An attacker can provide a crafted XCOFF file that triggers an OOB read, leading to a crash (DoS), information disclosure, or potentially unintended control flow if corrupted data is subsequently used as a function pointer. The issue is fixed in GNU Binutils version 2.47.

Affected products

  • GNU Binutils All versions prior to 2.47
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 6

Timeline

  • 2026-02-23: disclosed: Initial report on Sourceware Bugzilla
  • 2026-03-15: patched: Fix committed to GNU Binutils master branch
  • 2026-03-23: advisory: CVE published and Red Hat advisory issued

References

Related threats