MEDIUM
CVE-2026-90801
CVSS
6.6
Description
A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
CWE-120
Classic Buffer Overflow
EPSS Score
0.16%
Probability of exploitation in next 30 days
5.1th percentile
References
https://github.com/r1ck9-2q/cve_summit/blob/main/Heap-buffer-overflow%20in%20%60cache_bwrite%60%20(bfdcache.c436)%20via%20malformed%20ELF%20with%20%60--gc-sections%20-w%60.md
Exploit, Mitigation, Third Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=34442
Exploit, Third Party Advisory
https://vuldb.com/cve/CVE-2026-90801
Permissions Required, Third Party Advisory, VDB Entry
https://vuldb.com/submit/920276
Permissions Required, Third Party Advisory, VDB Entry
https://vuldb.com/vuln/403303
Permissions Required, Third Party Advisory, VDB Entry
https://vuldb.com/vuln/403303/cti
Permissions Required, Third Party Advisory, VDB Entry
https://www.gnu.org/
Product
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.