CVE-2026-3442

Source
https://cve.org/CVERecord?id=CVE-2026-3442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-3442
Downstream
Related
Published
2026-03-15T00:19:02.700Z
Modified
2026-07-16T03:30:58.762892697Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L CVSS Calculator
Summary
Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
Details

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3442.json",
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
a44161c313d46a1b10fd764728a089c26037710a
Last affected
1f1c02597cc199227226251a2ea51fe5f44b4d6d
Database specific
{
    "cpe": [
        "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        },
        {
            "introduced": "6.0"
        },
        {
            "last_affected": "6.0"
        },
        {
            "introduced": "7.0"
        },
        {
            "last_affected": "7.0"
        },
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.0"
        }
    ]
}

Affected versions

4.*
4.0
6.*
6.0
7.*
7.0
8.*
8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3442.json"