Vulnerability Details CVE-2026-90801
A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2026-90801
-
cpe:2.3:a:gnu:binutils:2.47