Description
In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buffer overflow out of bounds write.
Published: 2026-08-20
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In binutils version 2.46.1 and earlier a stack buffer overflow occurs in the rsrc_print_name function when processing a malicious PE file. The overflow writes beyond the bounds of a stack buffer, allowing an attacker to execute arbitrary code without direct interaction with the affected process. The flaw reveals a high severity vulnerability with a CVSS score of 7.8, meaning that exploitation could lead to full control of the machine running binutils.

Affected Systems

Red Hat products including the Migration Toolkit for Containers, Red Hat Enterprise Linux from version 6 through 10, Red Hat Hardened Images, and Red‑Hat OpenShift Container Platform 4 are affected when they ship with binutils 2.46.1 or earlier. Any instance of these products that has that version of binutils installed and processes a crafted Portable Executable file is vulnerable.

Risk and Exploitability

The vulnerability does not require network connectivity; an attacker simply needs the ability to invoke binutils on a crafted PE file. Because the description provides no indication of remote triggers, the likely attack vector is local or local‑user exploitation. The EPSS score is unavailable, and the flaw is not yet cataloged in CISA KEV, but the CVSS rating signals a high risk. Users who must process unknown or untrusted files with binutils should treat this with the same urgency as a remote code execution flaw.

Generated by OpenCVE AI on August 20, 2026 at 07:21 UTC.

Remediation

Vendor Workaround

Do not open unknown files and/or files from an untrusted source using binutils.


OpenCVE Recommended Actions

  • Avoid opening unknown or untrusted PE files with binutils.
  • Upgrade binutils to a fixed version (e.g., 2.47 or later) once it is released by Red Hat or the upstream project.
  • Run binutils with restricted privileges or in a sandbox environment to limit the impact of a potential exploit.

Generated by OpenCVE AI on August 20, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Description In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buffer overflow out of bounds write.
Title Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat rhmt
Weaknesses CWE-787
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/a:redhat:rhmt:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat rhmt
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Hummingbird Openshift Rhmt
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T04:55:06.769Z

Reserved: 2026-08-11T21:00:57.017Z

Link: CVE-2026-19582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T05:16:27.987

Modified: 2026-08-20T13:08:53.900

Link: CVE-2026-19582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T07:30:03Z

Weaknesses