Technology · Gnu
Gnu Binutils vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 36 vulnerabilities in Gnu Binutils: 0 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91782, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 0
- Exploited in the wild
- 0
About Gnu Binutils
A collection of binary tools for manipulating object files in various object file formats.
Latest Gnu Binutils vulnerabilities
- CVE-2026-91782: GNU Binutils null pointer dereference in dynamic relocation allocationlowCVSS 3.3EPSS 0.2%
- CVE-2026-91781: GNU Binutils null pointer dereference in ELF section handlerlowCVSS 3.3EPSS 0.2%
- CVE-2026-91780: GNU Binutils null pointer dereference in ELF linkerlowCVSS 3.3EPSS 0.2%
- CVE-2026-91779: GNU Binutils null pointer dereference in eh_frame section offsetlowCVSS 3.3EPSS 0.2%
- CVE-2026-90831: GNU Binutils memory corruption in ELF string table handlingmediumCVSS 5.3EPSS 0.2%
- CVE-2026-90830: GNU Binutils null pointer dereference in section mergemediumCVSS 5.3EPSS 0.2%
- CVE-2026-90829: GNU Binutils null pointer dereference in SHT_GROUP handlermediumCVSS 5.3EPSS 0.2%
- CVE-2026-90828: GNU Binutils null pointer dereference in ELF orphan section handlermediumCVSS 5.3EPSS 0.2%
- CVE-2026-90804: GNU Binutils heap buffer overflow in eh_frame handlermediumCVSS 4.8EPSS 0.2%
- CVE-2026-90803: GNU Binutils buffer overflow in elf_x86_64_relocate_sectionmediumCVSS 5.3EPSS 0.2%
- CVE-2026-90802: GNU Binutils ld null pointer dereference in bfd_putl64mediumCVSS 4.4EPSS 0.2%
- CVE-2026-90801: GNU Binutils ld heap buffer overflow in cache_bwritemediumCVSS 5.3EPSS 0.2%
- CVE-2026-19548: GNU binutils ld use-after-free in add_archive_elementmediumCVSS 5.5EPSS 0.2%
- CVE-2026-18220: GNU binutils out-of-bounds write in BFD DLX ELF backendhighCVSS 7.8
- CVE-2026-15003: GNU Binutils heap overflow in linker XCOFF processingmediumCVSS 5.6
- CVE-2026-6846: GNU binutils heap buffer overflow in xcoff_link_add_symbolshighCVSS 7.8EPSS 0.0%
- CVE-2026-6845: GNU binutils Denial of Service in readelfmediumCVSS 5EPSS 0.0%
- CVE-2026-6844: GNU binutils Denial of Service in readelfmediumCVSS 5.5EPSS 0.0%
- CVE-2026-4647: GNU Binutils BFD library out-of-bounds read in XCOFF relocation processingmediumCVSS 6.1EPSS 0.2%
- CVE-2026-3442: GNU Binutils out-of-bounds read in bfd linkermediumCVSS 6.1EPSS 0.2%
- CVE-2026-3441: GNU Binutils out-of-bounds read in BFD linkermediumCVSS 6.1EPSS 0.2%
- CVE-2025-11840: GNU Binutils out-of-bounds read in vfinfo functionlowCVSS 3.3
- CVE-2025-11839: GNU Binutils unchecked return value in tg_tag_typelowCVSS 3.3
- CVE-2025-11495: GNU Binutils heap overflow in Linker elf_x86_64_relocate_sectionlowCVSS 3.3
- CVE-2025-11494: GNU Binutils out-of-bounds read in Linker x86 ELF handlinglowCVSS 3.3
Most severe Gnu Binutils vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-6846: GNU binutils heap buffer overflow in xcoff_link_add_symbolshighCVSS 7.8EPSS 0.0%
- CVE-2026-18220: GNU binutils out-of-bounds write in BFD DLX ELF backendhighCVSS 7.8
- CVE-2026-3442: GNU Binutils out-of-bounds read in bfd linkermediumCVSS 6.1EPSS 0.2%
- CVE-2026-3441: GNU Binutils out-of-bounds read in BFD linkermediumCVSS 6.1EPSS 0.2%
- CVE-2026-4647: GNU Binutils BFD library out-of-bounds read in XCOFF relocation processingmediumCVSS 6.1EPSS 0.2%
- CVE-2026-15003: GNU Binutils heap overflow in linker XCOFF processingmediumCVSS 5.6
- CVE-2026-19548: GNU binutils ld use-after-free in add_archive_elementmediumCVSS 5.5EPSS 0.2%
- CVE-2026-6844: GNU binutils Denial of Service in readelfmediumCVSS 5.5EPSS 0.0%
- CVE-2026-90801: GNU Binutils ld heap buffer overflow in cache_bwritemediumCVSS 5.3EPSS 0.2%
- CVE-2026-90803: GNU Binutils buffer overflow in elf_x86_64_relocate_sectionmediumCVSS 5.3EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 12 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/binutils.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gnu Binutils vulnerabilities", https://junglewise.ai/threats/technologies/binutils, 26 September 2026.