CVE-2026-4647
đļ mediumSummary
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
CVSS Score
6.1
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2026-03-23
First Seen: 2026-03-24
đ Relative Risk Intelligence
This CVE is Lower Risk - more severe than 38.8% of all 318,332 vulnerabilities in our database.
#194,738
Below average severity
Severity Percentile
đ¯ CISA SSVC Assessment Updated: Mar 23, 2026
đ Exploitation Status
None
No known exploits
âī¸ Automatable
NO
Requires human interaction
đĨ Technical Impact
Partial
Limited system impact
đ Discovered By
Red Hat would like to thank Chen Zhengzhe (Hangzhou Dianzi University) for reporting this issue.
SSVC data provided by
CISA
Last Modified
2026-03-24
Source
NVD đ
CVSS Vector 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CWE IDs (Weakness Types)