Buffer Overflow in GNU Binutils ld Function Cache_bwrite
CVE-2026-90801
Key Information:
Badges
What is CVE-2026-90801?
A security vulnerability has been identified in GNU Binutils version 2.47 which affects the ld component's cache_bwrite function located in bfd/cache.c. This vulnerability arises from improper handling of the argument 'nbytes', leading to a buffer overflow condition. Exploiting this flaw requires local access to the system, and since the exploit has been made publicly available, it poses a significant risk to affected systems. Despite an early notification through a bug report, no corrective action has been taken by the project maintainers thus far.
Affected Version(s)
Binutils 2.47
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved