CVE-2026-56390

Name
CVE-2026-56390
Description
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cvd@cert.pl https://cert.pl/en/posts/2026/07/CVE-2026-56389
cvd@cert.pl https://cgit.git.savannah.gnu.org/cgit/bison.git/
cvd@cert.pl https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:bison:3.8.2:*:*:*:*:*:*:* bison == None == 3.8.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bison edge-main 3.8.2-r3 Achill Gilgenast <achill@achill.org> possibly vulnerable
bison edge-main 3.8.2-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
bison edge-main 3.8.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
bison 3.24-main 3.8.2-r3 Achill Gilgenast <achill@achill.org> possibly vulnerable
bison 3.23-main 3.8.2-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
bison 3.22-main 3.8.2-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
bison 3.21-main 3.8.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
bison 3.20-main 3.8.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
bison 3.19-main 3.8.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable