CVE-2026-3441
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2026-3441 is a heap-based buffer overflow (out-of-bounds read) vulnerability in GNU Binutils, specifically within the bfd linker component. The flaw resides in bfd/xcofflink.c in the xcoff_link_add_symbols function, triggered by processing a specially crafted XCOFF object file. It affects GNU Binutils (all versions tracked under CPE) and Red Hat Enterprise Linux 6.0 through 10.0, as well as Red Hat OpenShift Container Platform 4.0. Disclosed on March 2, 2026, it carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is an improper validation of the x_scnlen value in bfd/xcofflink.c, leading to an out-of-bounds read (CWE-125) on the csects array within the xcoff_link_add_symbols function. An attacker must convince a user to run the ld linker against a maliciously crafted XCOFF (Extended Common Object File Format) object file, making the attack vector local with required user interaction. The improper bounds check allows memory reads beyond the allocated buffer, potentially exposing sensitive heap contents or causing a denial of service (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can result in information disclosure — specifically, unauthorized access to sensitive data from heap memory — or an application-level denial of service (crash of the ld linker). The confidentiality and availability impacts are both rated High, while integrity is unaffected, as the vulnerability only enables reading beyond buffer boundaries rather than writing. The scope is limited to the affected application and does not enable lateral movement or privilege escalation on its own (Red Hat CVE, Red Hat Bugzilla).

Exploitation steps

  1. Craft malicious XCOFF file: Create a specially crafted XCOFF object file with an invalid or oversized x_scnlen value in the section header, designed to trigger an out-of-bounds read in the xcoff_link_add_symbols function of bfd/xcofflink.c.
  2. Social engineering: Convince a target user (e.g., a developer or build system operator) to link against the malicious XCOFF object file using the GNU ld linker (e.g., ld malicious.o -o output).
  3. Trigger the vulnerability: When ld processes the crafted file, the improper x_scnlen check causes an out-of-bounds read on the csects array, potentially leaking heap memory contents or crashing the linker.
  4. Collect output: If information disclosure is the goal, capture any error output, core dumps, or side-channel data that may contain sensitive heap memory contents from the linker process (Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .o XCOFF object files in build directories; core dump files (core, ld.core) generated by the ld linker process.
  • Logs: System logs or build logs showing ld crashes, segmentation faults, or abnormal termination when processing XCOFF files; error messages referencing xcofflink.c or xcoff_link_add_symbols.
  • Process: Unexpected termination of the ld linker process; ld spawning with unusual input files from untrusted or external sources.

Mitigation and workarounds

Red Hat has acknowledged the vulnerability and a patch is available, documented in Red Hat Bugzilla Bug ID 2443826. Organizations should apply vendor-supplied updates for affected Red Hat Enterprise Linux (versions 6–10) and OpenShift Container Platform 4.x packages containing GNU Binutils. As a workaround, limit local user access to build systems, avoid processing XCOFF object files from untrusted sources, and monitor build pipelines for unexpected input files (Red Hat CVE, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage from Linux security aggregators and distribution security lists, including Fedora update advisories (for the insight package) and Yocto Project security mailing list CVE metric reports. No notable researcher commentary or significant social media discussion has been identified beyond automated CVE tracking posts (Linux Security).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47063HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-jmods
NoYesJul 21, 2026
CVE-2026-47058HIGH7.4
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-devel
NoYesJul 21, 2026
CVE-2026-60147MEDIUM6.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-demo
NoYesJul 21, 2026
CVE-2026-47059LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-11-amazon-corretto
NoYesJul 21, 2026
CVE-2026-14957NONEN/A
  • Rocky Linux logoRocky Linux
  • libreswan
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management