A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-3442 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443828 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Mar 2026, 18:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://access.redhat.com/security/cve/CVE-2026-3442 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2443828 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat
Redhat enterprise Linux Gnu binutils Gnu Redhat openshift Container Platform |
|
| CPE | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:binutils:-:*:*:*:*:*:*:* |
|
| Summary |
|
16 Mar 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:19
Updated : 2026-03-20 18:23
NVD link : CVE-2026-3442
Mitre link : CVE-2026-3442
CVE.ORG link : CVE-2026-3442
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
gnu
- binutils
CWE
CWE-125
Out-of-bounds Read
