Back to overview

CVE-2026-15003

MEDIUM
5.6
CVSS 3.1
Description
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.

Metadata

CVE ID
CVE-2026-15003
State
PUBLISHED
Assigner
redhat
Reserved
2026-07-07 20:18 UTC
Published
2026-07-27 13:22 UTC
Last updated
2026-07-28 16:41 UTC
Primary CWE
CWE-125
Out-of-bounds Read
Vendor / Product
Red Hat / Red Hat Hardened Images
Sources
cve.org  ·  NVD

Severity & Metrics

5.6 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (23)
VendorProductPlatformVersions
Red Hat Red Hat Enterprise Linux 10 — —
Red Hat Red Hat Enterprise Linux 10 — —
Red Hat Red Hat Enterprise Linux 10 — —
Red Hat Red Hat Enterprise Linux 10 — —
Red Hat Red Hat Enterprise Linux 10 — —
Red Hat Red Hat Enterprise Linux 6 — —
Red Hat Red Hat Enterprise Linux 7 — —
Red Hat Red Hat Enterprise Linux 7 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 8 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Enterprise Linux 9 — —
Red Hat Red Hat Hardened Images — 2.46.1-1.1.hum1 < *
Red Hat Red Hat OpenShift Container Platform 4 — —
Weakness (CWE)
CWESourceDescription
CWE-125 cna Out-of-bounds Read
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.6 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
Back to overview