CVE-2026-15003: Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.
Other sources
Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.2-11
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-15003?
The risk level of CVE-2026-15003 is classified as medium with a severity score of 5.6.
What is CVE-2026-15003?
CVE-2026-15003 is a heap-buffer-overflow vulnerability in the GNU Binutils linker that can lead to information disclosure and denial of service.
How can I mitigate CVE-2026-15003?
To mitigate CVE-2026-15003, ensure that you update to the latest version of GNU Binutils as patches may be provided.
What are the potential impacts of CVE-2026-15003?
The potential impacts of CVE-2026-15003 include information disclosure and denial of service due to improper handling of specially crafted object files.
Who can be affected by CVE-2026-15003?
Users and systems that utilize the GNU Binutils linker to process 32-bit XCOFF object files may be affected by CVE-2026-15003.