{"id":"CVE-2026-13732","title":"A flaw was found in GDB's STABS debug format parser","summary":"A flaw was found in GDB's STABS debug format parser. The\nread_member_functions() function in gdb/stabsread.c contains a linked\nlist removal bug in the code that separates destructor and non-destructor\nmember functions of C++ classes. The…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"Red Hat","product":"gdb","affected":["gdb (all versions)","gdb (all versions)","gdb (all versions)","gdb (all versions)","gdb (all versions)","gdb (all versions)"],"published":"2026-08-31","updated":"2026-09-29","sourceUpdated":"2026-09-29T17:17:08.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13732","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:73425","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:73427","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-13732","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494416","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-01T14:33:22.469791Z"},"epss":0.00121,"epssPercentile":0.01679,"ingestedAt":"2026-09-29T16:39:33.274Z","slug":"CVE-2026-13732","body":"## Overview\n\nA flaw was found in GDB's STABS debug format parser. The\nread_member_functions() function in gdb/stabsread.c contains a linked\nlist removal bug in the code that separates destructor and non-destructor\nmember functions of C++ classes. The bug causes the destructor entries to\nremain in the main function list while the list length counter is\ndecremented, resulting in an out-of-bounds write when the function list\nis copied to its final allocated array. An attacker can craft an ELF\nbinary with malicious .stab and .stabstr sections that triggers this\nout-of-bounds write when a user opens the file in GDB and performs any\nsymbol-inspection operation such as setting a breakpoint. The inferior\nprocess does not need to be executed. Under controlled conditions, this\nwas demonstrated to achieve execution of arbitrary commands within the\nGDB process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}