Bug 2494416 (CVE-2026-13732)

Summary: CVE-2026-13732 gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, security-response-team, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2544475    
Bug Blocks:    
Deadline: 2026-08-06   

Description OSIDB Bzimport 2026-06-29 14:49:53 UTC
A flaw was found in the GDB STABS debug format parser. The
read_member_functions() function in gdb/stabsread.c processes C++ member
function lists from STABS symbol data. When a class contains both
destructor and non-destructor member functions, the code at lines
5086-5131 attempts to separate them into two lists. However, the linked
list removal logic has a bug: the `last_sublist` tracking variable is
updated to point to REMOVED destructor nodes instead of the previous
retained node, and the `continue` path for non-destructor nodes does not
update `last_sublist` at all. This causes destructor entries to remain
in the `sublist` linked list while the `length` variable is decremented
by `has_destructor`. In the subsequent copy loop (lines 5163-5166), the
allocated array has `length` elements but the loop iterates over all
remaining `sublist` entries (more than `length`). The loop index `i`
starts at `length` and decrements, going negative, causing writes before
the allocated obstack array. The written data consists of `struct fn_field`
members controlled by the attacker through crafted STABS strings. The
obstack underflow can corrupt chunk metadata including function pointers,
which are called on subsequent obstack operations, resulting in arbitrary
code execution. The vulnerability triggers automatically when GDB expands
partial symbol tables — any symbol-inspection command (break, ptype, info
functions) on a binary containing crafted .stab/.stabstr sections is
sufficient. The inferior process does not need to be executed.

    Upstream: https://sourceware.org/git/binutils-gdb.git
    Affected: gdb/stabsread.c (read_member_functions, lines 5086-5166)
    Confirmed on: GDB 16.3-1, Debian trixie, x86-64, glibc 2.41
    Reporter: JD Marsters (Bhut Red)