OSV-2026-973

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/binutils/OSV-2026-973.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-973
Published
2026-06-27T00:10:11.183882Z
Modified
2026-06-29T20:05:30.805716Z
Summary
Heap-buffer-overflow in bfd_getl16
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=528056360

Crash type: Heap-buffer-overflow READ 1
Crash state:
bfd_getl16
m32r_elf_generic_reloc
bfd_perform_relocation
References

Affected packages

OSS-Fuzz / binutils

Package

Name
binutils
Purl
pkg:generic/binutils

Affected ranges

Type
GIT
Repo
git://sourceware.org/git/binutils-gdb.git
Events

Affected versions

Other
binutils-2_44
binutils-2_45
binutils-2_45_1
binutils-2_46
binutils-2_46_1
gdb-16-branchpoint
gdb-17-branchpoint
gdb-15.*
gdb-15.2-release
gdb-16.*
gdb-16.1-release
gdb-16.2-release
gdb-16.3-release
gdb-17.*
gdb-17.1-release
gdb-17.2-release

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

introduced_range
"80f2ae843a3c0968b34db51e4bb62a4610fa685d:db856d41004301b3a56438efd957ef5cabb91530"
fixed_range
"e17f386d7ffdd9604a0aad15a76606b846a2b9ed:11f57b156514211af29b93588c0fee2f8b3e66e4"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/binutils/OSV-2026-973.yaml"