CVE-2026-6846 is a heap buffer overflow vulnerability in binutils that occurs when processing malicious XCOFF object files during the linking process. The flaw allows a local attacker to trigger arbitrary code execution or denial of service by convincing a user to process a specially crafted file. This vulnerability affects the binutils package, which is widely used in development and build toolchains across systems. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector and no special privileges required, though user interaction is necessary for exploitation. The attack is relatively straightforward to execute with low complexity, and successful exploitation could result in arbitrary code execution, unauthorized command execution, or system unavailability. The potential impact is significant across confidentiality, integrity, and availability. The vulnerability is not currently listed in the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.000140 indicates extremely low probability of exploitation compared to other CVEs, and community attention remains minimal, suggesting the threat landscape impact is currently low. However, the high CVSS score warrants timely patching as part of routine maintenance procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.46CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.