Memory Handling Flaw in GNU Binutils BFD Library Affects Multiple Tools
CVE-2026-4647
6.1MEDIUM
What is CVE-2026-4647?
A flaw exists in the GNU Binutils BFD library, a critical tool for manipulating binary files. The vulnerability arises during the processing of specially crafted XCOFF object files, where a relocation type value is inadequately validated. This may lead to memory access violations, causing crashes in affected applications or the potential exposure of sensitive information. Users of the library should prioritize applying necessary updates to mitigate any risks associated with this issue.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Chen Zhengzhe (Hangzhou Dianzi University) for reporting this issue.