Skip to content

CVE-2026-6846 on CTRL-OS 26.05

Aliases: CVE-2026-6846

Packages: binutils

Status: Plausible

Advisory Information

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

Updates

2026-06-03 18:40 CEST

Comment:

Upstream statement:

There's no security issue here.

  • https://bugzilla.redhat.com/show_bug.cgi?id=2460006#c5

From their security process documentation:

The tools assume that the input is to be trusted.

  • https://sourceware.org/git/?p=binutils-gdb.git;a=blob_plain;f=binutils/SECURITY.txt;hb=binutils-2_46

2026-06-03 18:35 CEST

Metadata changes:

  • Status for package binutils: “Plausible

2026-05-28 23:55 CEST

Metadata changes:

  • Status for package binutils: “New