CVE-2026-3442

Source
https://cve.org/CVERecord?id=CVE-2026-3442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-3442
Downstream
Related
Published
2026-03-15T00:19:02Z
Modified
2026-09-03T03:30:34Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L CVSS Calculator
Summary
Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
Details

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3442.json"
}
References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        },
        {
            "introduced": "6.0"
        },
        {
            "last_affected": "6.0"
        },
        {
            "introduced": "7.0"
        },
        {
            "last_affected": "7.0"
        },
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

4.*
4.0
6.*
6.0
7.*
7.0
8.*
8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3442.json"