Record summary

CVE-2026-19548 has a selected CVSS score of 5.5 (medium).

Description

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element: 1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable. An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE. The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 17
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10gcc-toolset-15-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10gcc-toolset-16-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10mingw-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6binutils

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8gcc-toolset-14-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8gcc-toolset-15-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8mingw-binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9binutils

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9gcc-toolset-14-binutils

Default status: affected

CVE ListVersion data not supplied

References

3