MEDIUM

CVE-2026-90801

Gnu Binutils 2026-09-14 CVSS v3.1
CVSS
6.6

Description

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error
CWE-120 Classic Buffer Overflow

EPSS Score

0.16%
Probability of exploitation in next 30 days
5.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE