REDHAT-BUG-2513754: Binutils vulnerability
Published Aug 11, 2026
·Updated
There's a flaw in binutils 2.46.1 in rsrcprintname() and rsrcparseentries() functions by which an attacker with local access or whom does not have local access but social engineers a victim to run binutils on a crafted PE file, can execute malicious code.
Affected Software
1 affected component
binutils=2.46.1
Event History
Aug 11, 2026
Data Sourced
via Red Hat·03:18 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Who is exposed to this issue?
Users or systems that run binutils on PE files are exposed if an attacker can obtain local access or can persuade a victim to process a crafted PE file with binutils.
2
What does exploitation require?
The attacker needs local access, or must socially engineer someone into running binutils against a maliciously crafted PE file. Successful exploitation can result in malicious code execution.