CVE-2026-3442

Published: March 6, 2026Last modified: April 2, 2026

Description

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.

Severity score breakdown

ParameterValue
Base score7.1
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbinutilsNot affected (2.39-r2)
25 LTSbinutilsNot affected (2.44-r0)
StreambinutilsNot affected (2.40-r4)
Hardened Containers23 LTSbinutilsNot affected (2.39-r2)
25 LTSbinutilsNot affected (2.44-r0)
StreambinutilsNot affected (2.40-r4)

References

ON THIS PAGE