
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3441 is a heap-based buffer overflow (out-of-bounds read) vulnerability in GNU Binutils, specifically within the bfd linker component. The flaw resides in bfd/xcofflink.c in the xcoff_link_add_symbols function, triggered by processing a specially crafted XCOFF object file. It affects GNU Binutils (all versions tracked under CPE) and Red Hat Enterprise Linux 6.0 through 10.0, as well as Red Hat OpenShift Container Platform 4.0. Disclosed on March 2, 2026, it carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, Red Hat Bugzilla).
The root cause is an improper validation of the x_scnlen value in bfd/xcofflink.c, leading to an out-of-bounds read (CWE-125) on the csects array within the xcoff_link_add_symbols function. An attacker must convince a user to run the ld linker against a maliciously crafted XCOFF (Extended Common Object File Format) object file, making the attack vector local with required user interaction. The improper bounds check allows memory reads beyond the allocated buffer, potentially exposing sensitive heap contents or causing a denial of service (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can result in information disclosure — specifically, unauthorized access to sensitive data from heap memory — or an application-level denial of service (crash of the ld linker). The confidentiality and availability impacts are both rated High, while integrity is unaffected, as the vulnerability only enables reading beyond buffer boundaries rather than writing. The scope is limited to the affected application and does not enable lateral movement or privilege escalation on its own (Red Hat CVE, Red Hat Bugzilla).
x_scnlen value in the section header, designed to trigger an out-of-bounds read in the xcoff_link_add_symbols function of bfd/xcofflink.c.ld linker (e.g., ld malicious.o -o output).ld processes the crafted file, the improper x_scnlen check causes an out-of-bounds read on the csects array, potentially leaking heap memory contents or crashing the linker..o XCOFF object files in build directories; core dump files (core, ld.core) generated by the ld linker process.ld crashes, segmentation faults, or abnormal termination when processing XCOFF files; error messages referencing xcofflink.c or xcoff_link_add_symbols.ld linker process; ld spawning with unusual input files from untrusted or external sources.Red Hat has acknowledged the vulnerability and a patch is available, documented in Red Hat Bugzilla Bug ID 2443826. Organizations should apply vendor-supplied updates for affected Red Hat Enterprise Linux (versions 6–10) and OpenShift Container Platform 4.x packages containing GNU Binutils. As a workaround, limit local user access to build systems, avoid processing XCOFF object files from untrusted sources, and monitor build pipelines for unexpected input files (Red Hat CVE, Red Hat Bugzilla).
The vulnerability received routine coverage from Linux security aggregators and distribution security lists, including Fedora update advisories (for the insight package) and Yocto Project security mailing list CVE metric reports. No notable researcher commentary or significant social media discussion has been identified beyond automated CVE tracking posts (Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."