CVE-2026-3442

Source
https://cve.org/CVERecord?id=CVE-2026-3442
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-3442.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-3442
Downstream
Related
Published
2026-03-15T00:19:02.700Z
Modified
2026-06-26T03:54:58.846523161Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L CVSS Calculator
Summary
Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
Details

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3442.json"
}
References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
a44161c313d46a1b10fd764728a089c26037710a
Last affected
497f816e7547ec80b87ff4be68e054ac00d03ea0
Last affected
a17fcd19400181f4b8b45be7715337ed83d7a122
Last affected
1f1c02597cc199227226251a2ea51fe5f44b4d6d
Database specific
{
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.0"
        },
        {
            "last_affected": "6.0"
        },
        {
            "last_affected": "7.0"
        },
        {
            "last_affected": "8.0"
        }
    ],
    "cpe": [
        "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
    ]
}

Affected versions

Other
gdb-4_18-branchpoint
gdb_5_2-branchpoint
gdb_5_3-branchpoint
gdb_6_0-branchpoint
gdb_6_1-branchpoint
gdb_6_2-branchpoint
gdb_6_3-branchpoint
gdb_6_4-branchpoint
gdb_6_5-branchpoint
gdb_6_6-branchpoint
gdb_6_7-branchpoint
gdb_6_8-branchpoint
gdb_7_0-branchpoint
gdb_7_1-branchpoint
gdb_7_2-branchpoint
gdb_7_3-branchpoint
gdb_7_4-branchpoint
gdb_7_5-branchpoint
gdb_7_6-branchpoint
readline_4_0
users/ARM/embedded-binutils-master-2016q4
gdb-7.*
gdb-7.10-branchpoint
gdb-7.11-branchpoint
gdb-7.12-branchpoint
gdb-7.7-branchpoint
gdb-7.8-branchpoint
gdb-7.9-branchpoint
gdb-8.*
gdb-8.0-branchpoint
gdb-8.0-release

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-3442.json"