CVE-2026-6846

Name
CVE-2026-6846
Description
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-6846
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2460006

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* binutils >= None <= 2.46
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* hardened_images == None == -
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* openshift_container_platform == None == 4.0
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* enterprise_linux == None == 6.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* enterprise_linux == None == 10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
binutils edge-main 2.45.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.45.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.45-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.43.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.40-r12 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r11 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r10 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r8 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r7 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r6 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r0 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r3 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r2 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r1 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r0 None possibly vulnerable
binutils edge-main 2.35.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.35.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.32-r0 None possibly vulnerable
binutils edge-main 2.28-r1 None possibly vulnerable
binutils 3.23-main 2.45.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.40-r10 None possibly vulnerable
binutils 3.22-main 2.40-r0 None possibly vulnerable
binutils 3.22-main 2.39-r2 None possibly vulnerable
binutils 3.22-main 2.39-r0 None possibly vulnerable
binutils 3.22-main 2.35.2-r1 None possibly vulnerable
binutils 3.22-main 2.32-r0 None possibly vulnerable
binutils 3.22-main 2.28-r1 None possibly vulnerable
binutils 3.21-main 2.43.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.43.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.43.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.40-r10 None possibly vulnerable
binutils 3.21-main 2.40-r0 None possibly vulnerable
binutils 3.21-main 2.39-r2 None possibly vulnerable
binutils 3.21-main 2.39-r0 None possibly vulnerable
binutils 3.21-main 2.35.2-r1 None possibly vulnerable
binutils 3.21-main 2.32-r0 None possibly vulnerable
binutils 3.21-main 2.28-r1 None possibly vulnerable
binutils 3.20-main 2.42-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.20-main 2.42-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.20-main 2.40-r10 None possibly vulnerable
binutils 3.20-main 2.40-r0 None possibly vulnerable
binutils 3.20-main 2.39-r2 None possibly vulnerable
binutils 3.20-main 2.39-r0 None possibly vulnerable
binutils 3.20-main 2.35.2-r1 None possibly vulnerable
binutils 3.20-main 2.32-r0 None possibly vulnerable
binutils 3.20-main 2.28-r1 None possibly vulnerable
binutils 3.19-main 2.41-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.19-main 2.41-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.19-main 2.40-r10 None possibly vulnerable
binutils 3.19-main 2.40-r0 None possibly vulnerable
binutils 3.19-main 2.39-r2 None possibly vulnerable
binutils 3.19-main 2.39-r0 None possibly vulnerable
binutils 3.19-main 2.35.2-r1 None possibly vulnerable
binutils 3.19-main 2.32-r0 None possibly vulnerable
binutils 3.19-main 2.28-r1 None possibly vulnerable