CVE-2026-6846
published 2026-04-22CVE-2026-6846: A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.17%
6.7th percentile
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | binutils | <= 2.46 | — |
| gnu | binutils | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
vendor_redhat·2026-04-08·CVSS 7.8
CVE-2026-6846 [HIGH] CWE-122 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: binutils (Red Hat Enterprise Linux 10) -
GHSA
GHSA-c64w-hpm6-xx8w: A flaw was found in binutils
ghsa_unreviewed·2026-04-22
CVE-2026-6846 [HIGH] CWE-122 GHSA-c64w-hpm6-xx8w: A flaw was found in binutils
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Note - the SECURITY policy for the GNU Binutils project rules out this CVE from being considered a security issue. Whilst the bug can cause the linker to crash, it cannot cause the linker to generate a compromised binary, nor can it be used to comprise the system's security or start a denial of service.
Bugzilla
CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
CVE-2026-6846 rizin: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 mingw-binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 mingw-binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 mingw-binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 gdb: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 gdb: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 gdb: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
CVE-2026-6846 radare2: Binutils: Arbitrary code execution via malformed XCOFF object file processing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 insight: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
bugzilla·2026-04-22·CVSS 7.8
CVE-2026-6846 [HIGH] CVE-2026-6846 insight: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
CVE-2026-6846 insight: Binutils: Arbitrary code execution via malformed XCOFF object file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
bugzilla·2026-04-21·CVSS 5.0
CVE-2026-6846 [MEDIUM] CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
CVE-2026-6846 binutils: Binutils: Arbitrary code execution via malformed XCOFF object file processing
Heap-buffer-overflow WRITE in xcoff_link_add_symbols() in bfd/xcofflink.c. Triggered by malformed XCOFF object file during linking. Fixed upstream by Alan Modra.
Public reference: https://sourceware.org/bugzilla/show_bug.cgi?id=34049
Affects binutils <= 2.46.
Discussion:
There's no security issue here, please review the binutils and gdb security policies:
https://sourceware.org/git/?p=binutils-gdb.git;a=blob_plain;f=binutils/SECURITY.txt;hb=HEAD
https://sourceware.org/git/?p=binutils-gdb.git;a=blob_plain;f=gdb/SECURITY.txt;hb=HEAD
Same for CVE-2026-6845, please lets not issue CVE numbers for binutils and gdb like this, it's just a waste of time for everyone.
https://access.redhat.com/errata/RHSA-2026:33527https://access.redhat.com/errata/RHSA-2026:39022https://access.redhat.com/security/cve/CVE-2026-6846https://bugzilla.redhat.com/show_bug.cgi?id=2460006https://access.redhat.com/errata/RHSA-2026:33527https://access.redhat.com/security/cve/CVE-2026-6846https://bugzilla.redhat.com/show_bug.cgi?id=2460006https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json
2026-04-22
Published