CVE-2026-4647
published 2026-03-23CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when…
PriorityP426medium6.1CVSS 3.1
AVLACLPRNUIRSUCLINAH
EPSS
0.17%
6.4th percentile
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_crash_9.0.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_gdb_13.2-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_crash_8.0.1-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gdb_11.2-10_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
osv·2026-03-23·CVSS 6.1
CVE-2026-4647 [MEDIUM] CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
GHSA
GHSA-v858-p3pc-hqjh: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
ghsa_unreviewed·2026-03-23
CVE-2026-4647 [MEDIUM] CWE-125 GHSA-v858-p3pc-hqjh: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Red Hat
binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
vendor_redhat·2026-03-23·CVSS 6.1
CVE-2026-4647 [MEDIUM] CWE-125 binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, w
Microsoft
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
vendor_msrc·2026-03-10·CVSS 6.1
CVE-2026-4647 [MEDIUM] CWE-125 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2026-4647: binutils - A flaw was found in the GNU Binutils BFD library, a widely used component for ha...
vendor_debian·2026·CVSS 6.1
CVE-2026-4647 [MEDIUM] CVE-2026-4647: binutils - A flaw was found in the GNU Binutils BFD library, a widely used component for ha...
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-4647 binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
bugzilla·2026-03-23·CVSS 6.1
CVE-2026-4647 [MEDIUM] CVE-2026-4647 binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
CVE-2026-4647 binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
An out-of-bounds read vulnerability in the BFD library of GNU Binutils affects the functions xcoff_ppc_relocate_section() and xcoff64_ppc_relocate_section() in coff-rs6000.c and coff64-rs6000.c. The flaw is caused by improper validation of the relocation type field (r_type), which is read from input files and used as an array index without adequate bounds checking. This issue affects all versions of GNU Binutils prior to 2.47. When a specially crafted XCOFF object file is processed, this can lead to out-of-bounds memory access, potentially causing a crash, information disclosure, or unintended control flow behavior.
Discussion:
The functions xcoff_ppc_relocate_section() and xcoff64_ppc_
Bugzilla
CVE-2026-4647 mingw-binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library [fedora-all]
bugzilla·2026-03-23·CVSS 6.1
CVE-2026-4647 [MEDIUM] CVE-2026-4647 mingw-binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library [fedora-all]
CVE-2026-4647 mingw-binutils: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback for this
Wiz
CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4647 [MEDIUM] CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4647 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Source : NVD
## 6.1
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV
Wiz
CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3441 [MEDIUM] CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3441 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3442 [MEDIUM] CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3442 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploit
2026-03-23
Published