CVE-2026-4647

Published Mar 23, 2026

Last updated a day ago

Overview

Description
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Source
secalert@redhat.com
NVD status
Analyzed
Products
binutils, openshift_container_platform, enterprise_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
4.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-125

Social media

Hype score
Not currently trending

Configurations