Description
A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution through local buffer overflow
Action: Apply patch
AI Analysis

Impact

A buffer overflow occurs in the cache_bwrite() function of GNU Binutils ld when the nbytes parameter is manipulated. The overflow can corrupt memory, potentially allowing an attacker to overwrite return addresses or other control data, which may lead to remote code execution or execution of arbitrary code. The flaw is classified as CWE-119 and CWE-120 and carries a CVSS score of 4.8, indicating moderate severity. The attack is local in nature but the public release of the exploit means that compromised systems could be used to facilitate further attacks.

Affected Systems

The vulnerability affects GNU Binutils version 2.47 across all platforms supported by the library, as identified by the CPE cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* and the vendor product listing GNU:Binutils. No specific sub‑versions beyond 2.47 are listed; therefore earlier releases are assumed unaffected, but verification is recommended.

Risk and Exploitability

The CVSS score of 4.8 shows that the vulnerability is moderate; however, the exploit is publicly available which increases the risk of real‑world usage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its local nature and public release raise concern for environments that handle untrusted ELF files. The attack path involves an adversary with local access injecting a malformed ELF file that triggers the cache_bwrite overflow while the linker is invoked with a malicious --gc-sections -w parameter. Successful exploitation can lead to arbitrary code execution on the vulnerable system.

Generated by OpenCVE AI on September 15, 2026 at 07:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GNU Binutils to a version where cache_bwrite has been fixed; current releases after 2.47 should contain the patch.
  • If an upgrade is not immediately possible, avoid using the --gc-sections -w option with untrusted ELF files or implement an integrity check that validates ELF files before they reach the linker.
  • Apply any vendor‑issued security patches or source‑code patches that address the buffer overflow; if none are available, consider patching the affected source file locally and recompiling the toolchain.

Generated by OpenCVE AI on September 15, 2026 at 07:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils ld cache.c cache_bwrite buffer overflow
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:32:57.245Z

Reserved: 2026-09-13T15:33:38.779Z

Link: CVE-2026-90801

cve-icon Vulnrichment

Updated: 2026-09-14T16:32:53.202Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T17:17:56.610

Modified: 2026-09-18T14:42:27.257

Link: CVE-2026-90801

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T16:15:14Z

Links: CVE-2026-90801 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:15:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')