PT-2026-64906 · Gnu · Gnu Binutils

CVE-2026-15003

·

Published

2026-07-27

·

Updated

2026-08-31

CVSS v3.1

5.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils (affected versions not specified)
Description A heap-buffer-overflow read occurs in the linker when processing a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker can provide a malicious file to trigger an out-of-bounds read of memory, which may lead to information disclosure of sensitive heap data or a Denial of Service (DoS) causing the linker to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94187
AZL-94211
CVE-2026-15003
ECHO-A285-B836-7FDB
OESA-2026-3255
OESA-2026-3256
OESA-2026-3257
OESA-2026-3314
OESA-2026-3315
RHSA-2026:47171

Affected Products

Gnu Binutils