CVE-2026-3442
published 2026-03-16CVE-2026-3442: A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An…
PriorityP427high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.26%
17.0th percentile
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
vendor_redhat·2026-03-02·CVSS 6.1
CVE-2026-3442 [MEDIUM] CWE-125 binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object
Debian
CVE-2026-3442: binutils - A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overfl...
vendor_debian·2026·CVSS 6.1
CVE-2026-3442 [MEDIUM] CVE-2026-3442: binutils - A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overfl...
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-j3rv-75wm-77rm: A flaw was found in GNU Binutils
ghsa_unreviewed·2026-03-16
CVE-2026-3442 [MEDIUM] CWE-125 GHSA-j3rv-75wm-77rm: A flaw was found in GNU Binutils
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
OSV
CVE-2026-3442: A flaw was found in GNU Binutils
osv·2026-03-16·CVSS 7.1
CVE-2026-3442 [HIGH] CVE-2026-3442: A flaw was found in GNU Binutils
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4647 [MEDIUM] CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4647 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Source : NVD
## 6.1
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV
Wiz
CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3441 [MEDIUM] CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3441 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3442 [MEDIUM] CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3442 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploit
Bugzilla
CVE-2026-3442 binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
bugzilla·2026-03-02·CVSS 7.1
CVE-2026-3442 [HIGH] CVE-2026-3442 binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
CVE-2026-3442 binutils: GNU Binutils: Information disclosure or denial of service via out-of-bounds read in bfd linker
Summary: A separate heap-based buffer overflow (Out-of-Bounds Read) was found in GNU Binutils (bfd linker) in bfd/xcofflink.c. This issue occurs in xcoff_link_add_symbols (approx line 2282) where r_symndx is used to index symbol hashes without sufficient bounds checking.
Requirements to exploit: An attacker needs to trick a user into running the ld linker against a specially crafted malicious XCOFF object file.
2026-03-16
Published