CVE-2026-6846

EUVD-2026-24714
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
gnubinutils
𝑥
≤ 2.46
redhathardened_images
-
redhatopenshift_container_platform
4.0
redhatenterprise_linux
6.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Hardened Images
2.45.1-5.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
2.46.1-1.hum1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
binutils
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Azure Linux logo
Azure Linux Releases
Azure Package
Release
binutils
Azure Linux 3.0
0:2.41-12.azl3
fixed
gdb
Azure Linux 3.0
0:13.2-8.azl3
fixed