CVE-2026-6846Disclosure(gnu / binutils)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu binutils systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • binutils
  • enterprise_linux
  • hardened_images
  • openshift_container_platform

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-22); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
binutilsenterprise_linuxhardened_imagesopenshift_container_platform

6 versions affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-22: 2Mentions · 2026-05-03: 2Mentions · 2026-07-30: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-04-22: 2Technical Details · 2026-05-03: 1Technical Details · 2026-07-30: 104-2205-0307-30
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure2
2026-05-032
General1Patch1
2026-07-301
Disclosure1
Full discourse5 posts
  • PatchHawk@patchhawk_
    Disclosure

    The 2 with CVEs: a heap overflow (CVE-2026-6846) and an OOB read (CVE-2026-15003) in XCOFF symbol loading. The 2 without: a symbol index used with no bound check, and a csect index tested against a byte offset, not a count. Same function. Same class. No CVE. https://t.co/AEJB1pjIqJ

    Post summary

    The tweet names two CVEs involving a heap overflow and an out‑of‑bounds read in XCOFF symbol loading, but provides no PoC, exploit, patch, or evidence of active exploitation.

    14030372
    65 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    Fedora sysadmins: A code execution flaw (CVE-2026-6846) affects the Insight debugger. Read more-> https://tinyurl.com/yeymucyb #Fedora #Security https://t.co/r5Wt26wEcP

    Post summary

    A tweet informs Fedora sysadmins of a code execution flaw (CVE-2026-6846) affecting the Insight debugger and provides a link for more information, but delivers no PoC, exploit, patch, or detailed technical data.

    0000041
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical CVE-2026-6846 in Fedora Insight on Fedora 42 and 43 allows arbitrary code execution via malformed XCOFF files, patch released April 24, 2026 via dnf update. https://threatcluster.io/cluster/critical-cve-2026-6846-vulnerability-in-fedora-insight-explo-13c4abeb

    Post summary

    The post announces the critical CVE-2026-6846 affecting Fedora Insight, details its arbitrary code execution via malformed XCOFF files, and notes that a patch is available through dnf update.

    0000083
    182 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6846 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file dur… https://www.cve.org/CVERecord?id=CVE-2026-6846 ----- Traducción: CVE-2026-6846 Se … http://infoflow.cloud`

    Post summary

    A heap‑buffer‑overflow flaw was identified in binutils that affects handling of XCOFF files; the post provides the CVE number and a brief technical description but no exploitation details, PoC, or patch information.

    0000034
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6846 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file dur… https://www.cve.org/CVERecord?id=CVE-2026-6846

    Post summary

    A heap‑buffer‑overflow vulnerability (CVE‑2026‑6846) was identified in binutils, triggered by specially crafted XCOFF files.

    00000209
    57.2K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appgnubinutils---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--

Explore more