CVE-2026-6846 on CTRL-OS 26.05
Aliases: CVE-2026-6846
Packages: binutils
Status: Plausible
Advisory Information
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
Updates
2026-06-03 18:40 CEST
Comment:
Upstream statement:
There's no security issue here.
- https://bugzilla.redhat.com/show_bug.cgi?id=2460006#c5
From their security process documentation:
The tools assume that the input is to be trusted.
- https://sourceware.org/git/?p=binutils-gdb.git;a=blob_plain;f=binutils/SECURITY.txt;hb=binutils-2_46
2026-06-03 18:35 CEST
Metadata changes:
- Status for package
binutils: “Plausible”
2026-05-28 23:55 CEST
Metadata changes:
- Status for package
binutils: “New”