CVE-2026-3442 - Vulnerability Analysis
MediumCVSS: 6.1Last Updated: March 16, 2026
GNU Binutils - Out-of-Bounds Read
Published: March 16, 2026Updated: March 16, 2026PoC Available
Overview
GNU Binutils contains a heap-based buffer overflow caused by an out-of-bounds read in the bfd linker component, letting attackers cause denial of service or information disclosure, exploit requires user to process a malicious XCOFF object file.
Severity & Score
Severity: Medium
CVSS Score: 6.1
Impact
Attackers can cause application crash or disclose sensitive information, leading to denial of service or information leakage.
Mitigation
Update to the latest version of GNU Binutils.
References
Related Resources
Details
- CVE ID
- CVE-2026-3442
- Severity
- Medium
- CVSS Score
- 6.1
- Type
- out_of_bounds_rw
- Status
- unconfirmed
CWE
- CWE-125
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L