Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6846

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Версия до 2.46 (включая)
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00171
Низкий

7.8 High

CVSS3

Дефекты

CWE-122
CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

CVSS3: 7.8
redhat
4 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

CVSS3: 7.8
msrc
3 месяца назад

Binutils: binutils: arbitrary code execution via malformed xcoff object file processing

CVSS3: 7.8
debian
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exi ...

CVSS3: 7.8
github
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

EPSS

Процентиль: 7%
0.00171
Низкий

7.8 High

CVSS3

Дефекты

CWE-122
CWE-122