Vulnerability Details CVE-2026-6846
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.7%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-6846
-
-
cpe:2.3:a:gnu:binutils:2.10
-
cpe:2.3:a:gnu:binutils:2.10.1
-
cpe:2.3:a:gnu:binutils:2.10.1a
-
cpe:2.3:a:gnu:binutils:2.11
-
cpe:2.3:a:gnu:binutils:2.11.1
-
cpe:2.3:a:gnu:binutils:2.11.2
-
cpe:2.3:a:gnu:binutils:2.11.2a
-
cpe:2.3:a:gnu:binutils:2.12
-
cpe:2.3:a:gnu:binutils:2.12.1
-
cpe:2.3:a:gnu:binutils:2.12.1a
-
cpe:2.3:a:gnu:binutils:2.13
-
cpe:2.3:a:gnu:binutils:2.13.1
-
cpe:2.3:a:gnu:binutils:2.13.2
-
cpe:2.3:a:gnu:binutils:2.13.2.1
-
cpe:2.3:a:gnu:binutils:2.13.2.1a
-
cpe:2.3:a:gnu:binutils:2.14
-
cpe:2.3:a:gnu:binutils:2.14a
-
cpe:2.3:a:gnu:binutils:2.15
-
cpe:2.3:a:gnu:binutils:2.15a
-
cpe:2.3:a:gnu:binutils:2.16.1
-
cpe:2.3:a:gnu:binutils:2.16.1a
-
cpe:2.3:a:gnu:binutils:2.17
-
cpe:2.3:a:gnu:binutils:2.17a
-
cpe:2.3:a:gnu:binutils:2.18
-
cpe:2.3:a:gnu:binutils:2.18a
-
cpe:2.3:a:gnu:binutils:2.19
-
cpe:2.3:a:gnu:binutils:2.19.1
-
cpe:2.3:a:gnu:binutils:2.19.1a
-
cpe:2.3:a:gnu:binutils:2.20
-
cpe:2.3:a:gnu:binutils:2.20.1
-
cpe:2.3:a:gnu:binutils:2.20.1a
-
cpe:2.3:a:gnu:binutils:2.21.1
-
cpe:2.3:a:gnu:binutils:2.21.1a
-
cpe:2.3:a:gnu:binutils:2.22
-
cpe:2.3:a:gnu:binutils:2.23
-
cpe:2.3:a:gnu:binutils:2.23.1
-
cpe:2.3:a:gnu:binutils:2.23.2
-
cpe:2.3:a:gnu:binutils:2.24
-
cpe:2.3:a:gnu:binutils:2.25
-
cpe:2.3:a:gnu:binutils:2.25.1
-
cpe:2.3:a:gnu:binutils:2.26
-
cpe:2.3:a:gnu:binutils:2.26.1
-
cpe:2.3:a:gnu:binutils:2.27
-
cpe:2.3:a:gnu:binutils:2.28
-
cpe:2.3:a:gnu:binutils:2.28.1
-
cpe:2.3:a:gnu:binutils:2.29
-
cpe:2.3:a:gnu:binutils:2.29.1
-
cpe:2.3:a:gnu:binutils:2.29.1.1
-
cpe:2.3:a:gnu:binutils:2.30
-
cpe:2.3:a:gnu:binutils:2.31
-
cpe:2.3:a:gnu:binutils:2.31.1
-
cpe:2.3:a:gnu:binutils:2.32
-
cpe:2.3:a:gnu:binutils:2.33
-
cpe:2.3:a:gnu:binutils:2.33.1
-
cpe:2.3:a:gnu:binutils:2.34
-
cpe:2.3:a:gnu:binutils:2.35
-
cpe:2.3:a:gnu:binutils:2.35.1
-
cpe:2.3:a:gnu:binutils:2.35.2
-
cpe:2.3:a:gnu:binutils:2.36
-
cpe:2.3:a:gnu:binutils:2.36.1
-
cpe:2.3:a:gnu:binutils:2.37
-
cpe:2.3:a:gnu:binutils:2.38
-
cpe:2.3:a:gnu:binutils:2.38.50
-
cpe:2.3:a:gnu:binutils:2.39
-
cpe:2.3:a:gnu:binutils:2.40
-
cpe:2.3:a:gnu:binutils:2.41
-
cpe:2.3:a:gnu:binutils:2.42
-
cpe:2.3:a:gnu:binutils:2.43
-
cpe:2.3:a:gnu:binutils:2.43.1
-
cpe:2.3:a:gnu:binutils:2.44
-
cpe:2.3:a:gnu:binutils:2.45
-
cpe:2.3:a:gnu:binutils:2.6
-
cpe:2.3:a:gnu:binutils:2.7
-
cpe:2.3:a:gnu:binutils:2.8
-
cpe:2.3:a:gnu:binutils:2.8.1
-
cpe:2.3:a:gnu:binutils:2.9
-
cpe:2.3:a:gnu:binutils:2.9.1
-
cpe:2.3:a:redhat:hardened_images:-
-
cpe:2.3:a:redhat:openshift_container_platform:4.0
-
cpe:2.3:o:redhat:enterprise_linux:10.0
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux:9.0