REDHAT-BUG-2497805: Medium severity GNU Binutils (Binary Utilities) linker vulnerability
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2497805?
The severity of REDHAT-BUG-2497805 is medium, rated at 4.
How does REDHAT-BUG-2497805 impact systems?
REDHAT-BUG-2497805 can lead to a heap-buffer-overflow read when processing specially crafted 32-bit XCOFF object files.
How can I mitigate REDHAT-BUG-2497805?
Mitigation for REDHAT-BUG-2497805 involves avoiding the processing of untrusted XCOFF object files and applying updates from the GNU project.
What software is affected by REDHAT-BUG-2497805?
REDHAT-BUG-2497805 affects the GNU Binutils (Binary Utilities) linker.
When was REDHAT-BUG-2497805 published?
REDHAT-BUG-2497805 was published on July 7, 2026.