CVE-2026-3441
published 2026-03-16CVE-2026-3441: A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to…
PriorityP430high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.18%
8.2th percentile
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8444-p2rx-h3vp: A flaw was found in GNU Binutils
ghsa_unreviewed·2026-03-16
CVE-2026-3441 [MEDIUM] CWE-125 GHSA-8444-p2rx-h3vp: A flaw was found in GNU Binutils
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
OSV
CVE-2026-3441: A flaw was found in GNU Binutils
osv·2026-03-16·CVSS 7.1
CVE-2026-3441 [HIGH] CVE-2026-3441: A flaw was found in GNU Binutils
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Red Hat
binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
vendor_redhat·2026-03-02·CVSS 6.1
CVE-2026-3441 [MEDIUM] CWE-125 binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading
Debian
CVE-2026-3441: binutils - A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability,...
vendor_debian·2026·CVSS 6.1
CVE-2026-3441 [MEDIUM] CVE-2026-3441: binutils - A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability,...
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4647 [MEDIUM] CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4647 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Source : NVD
## 6.1
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV
Wiz
CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3441 [MEDIUM] CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3441 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3442 [MEDIUM] CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3442 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploit
Bugzilla
CVE-2026-3441 binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
bugzilla·2026-03-02·CVSS 7.1
CVE-2026-3441 [HIGH] CVE-2026-3441 binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
CVE-2026-3441 binutils: GNU Binutils: Information disclosure via specially crafted XCOFF object file
Summary: A heap-based buffer overflow (Out-of-Bounds Read) was found in GNU Binutils (bfd linker). The vulnerability occurs in bfd/xcofflink.c in the xcoff_link_add_symbols function. It is caused by an improper check of the x_scnlen value, leading to an out-of-bounds access on the csects array.
Requirements to exploit: An attacker needs to trick a user into running the ld linker against a specially crafted malicious XCOFF object file.
2026-03-16
Published