Improper Handling of Output Paths in GNU Bison by GNU
CVE-2026-56390

4.6MEDIUM

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-56390?

GNU Bison contains a vulnerability related to the handling of grammar-defined output paths. The %output and %header directives can indiscriminately accept file paths, allowing attackers to direct generated files to arbitrary writable locations within the file system. This flaw can lead to the overwriting of existing files accessible to the Bison process when processing maliciously crafted grammar. While a patch has been provided by the maintainers, the specific range of affected versions is not fully disclosed, although version 3.8.2 has been confirmed as vulnerable.

Affected Version(s)

Bison 3.8.2

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
.