Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6846

31
FAUCET Score

CVE-2026-6846 is a heap buffer overflow vulnerability in binutils that occurs when processing malicious XCOFF object files during the linking process. The flaw allows a local attacker to trigger arbitrary code execution or denial of service by convincing a user to process a specially crafted file. This vulnerability affects the binutils package, which is widely used in development and build toolchains across systems. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector and no special privileges required, though user interaction is necessary for exploitation. The attack is relatively straightforward to execute with low complexity, and successful exploitation could result in arbitrary code execution, unauthorized command execution, or system unavailability. The potential impact is significant across confidentiality, integrity, and availability. The vulnerability is not currently listed in the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.000140 indicates extremely low probability of exploitation compared to other CVEs, and community attention remains minimal, suggesting the threat landscape impact is currently low. However, the high CVSS score warrants timely patching as part of routine maintenance procedures.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.46CPE matchmatch criteria
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 5th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: azl3 gdb 13.2-7 on Azure Linux 3.0Fixed in: 13.2-8
microsoftpatch availablevia msrc
Product: azl3 binutils 2.41-11 on Azure Linux 3.0Fixed in: 2.41-12
microsoftpatch availablevia msrc
Product: 21201-17084Fixed in: 13.2-8
microsoftpatch availablevia msrc
Product: 21200-17084Fixed in: 2.41-12

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-6846Important

Binutils: binutils: arbitrary code execution via malformed xcoff object file processing

Apr 14, 2026

References

security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6846.json
access.redhat.com / errata/RHSA-2026:33527
access.redhat.com / errata/RHSA-2026:39022
access.redhat.com / security/cve/CVE-2026-6846
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory