Bug 2513754 (CVE-2026-19582) - CVE-2026-19582 binutils: Stack Buffer Overflow in GNU Binutils in rsrc_print_name from an untrusted PE file
Summary: CVE-2026-19582 binutils: Stack Buffer Overflow in GNU Binutils in rsrc_print_...
Keywords:
Status: NEW
Alias: CVE-2026-19582
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2519346 2519347 2519348 2519349 2519351 2519352 2519353 2519354 2519355 2519356 2519360 2519361 2519362 2519363 2519364 2519365 2519350 2519366
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-11 03:18 UTC by OSIDB Bzimport
Modified: 2026-09-04 03:34 UTC (History)
28 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-11 03:18:30 UTC
There's a flaw in binutils 2.46.1 in rsrc_print_name() and rsrc_parse_entries() functions by which an attacker with local access or whom does not have local access but social engineers a victim to run binutils on a crafted PE file, can execute malicious code.

Comment 5 Todd Cullum 2026-08-25 22:11:30 UTC
There is no impact to Confidential, Integrity, or Availability due to upstream security policy which explicitly states that no security boundary is crossed in the case of this bug.

Comment 6 Nick Clifton 2026-09-02 08:57:06 UTC
Fix upstream by commit eda3758e23c

Will be brought in to rawhide as part of the next rebase of the binutils package.


Note You need to log in before you can comment on or make changes to this bug.