LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3442 - Vulnerability Analysis

MediumCVSS: 6.1

Last Updated: March 16, 2026

GNU Binutils - Out-of-Bounds Read

Published: March 16, 2026Updated: March 16, 2026PoC Available

Overview

GNU Binutils contains a heap-based buffer overflow caused by an out-of-bounds read in the bfd linker component, letting attackers cause denial of service or information disclosure, exploit requires user to process a malicious XCOFF object file.

Severity & Score

Severity: Medium
CVSS Score: 6.1

Impact

Attackers can cause application crash or disclose sensitive information, leading to denial of service or information leakage.

Mitigation

Update to the latest version of GNU Binutils.

Details

CVE ID
CVE-2026-3442
Severity
Medium
CVSS Score
6.1
Type
out_of_bounds_rw
Status
unconfirmed

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L