Bug 2497805 (CVE-2026-15003) - CVE-2026-15003 binutils: GNU Binutils: Heap-buffer-overflow in linker leads to information disclosure and denial of service
Summary: CVE-2026-15003 binutils: GNU Binutils: Heap-buffer-overflow in linker leads t...
Keywords:
Status: NEW
Alias: CVE-2026-15003
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-07 20:21 UTC by OSIDB Bzimport
Modified: 2026-07-27 13:17 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-07 20:21:08 UTC
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.


Note You need to log in before you can comment on or make changes to this bug.