CVE-2026-6846High· 7.8▾ TwilightA flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
binutils <= 2.46hardened_imagesopenshift_container_platform = 4.0enterprise_linux = 6.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-4647Medium· 6.1A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
CVE-2026-3442Medium· 6.1A flaw was found in GNU Binutils
CVE-2026-3441Medium· 6.1A flaw was found in GNU Binutils
CVE-2026-91780Low· 3.3A weakness has been identified in GNU Binutils 2.47
CVE-2026-91781Low· 3.3A security vulnerability has been detected in GNU Binutils 2.47
CVE-2026-91782Low· 3.3A vulnerability was detected in GNU Binutils 2.47