CVE-2026-13732 is an out-of-bounds write vulnerability in the GNU Debugger (GDB) STABS debug-format parser. Incorrect linked-list removal in read_member_functions() causes destructor entries to remain in the primary C++ member-function list while its length counter is decremented. When GDB copies the list into its final allocated array, the inconsistent list state produces an out-of-bounds write. A crafted ELF binary carrying malicious STABS debug sections can trigger the flaw during symbol inspection without executing the debugged inferior process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An out-of-bounds write vulnerability in GDB's parser for the STABS debugging format that can be triggered using a crafted ELF binary. Rocky Linux 8 GDB packages are affected.
An out-of-bounds write vulnerability in GDB's STABS parser, specifically the read_member_functions() function, that can be triggered through a crafted ELF file.
An out-of-bounds write vulnerability in GDB's STABS parser, specifically read_member_functions(), which can be triggered by a crafted ELF file. Rocky Linux 10.2 systems with affected GDB packages require the CIQ/Rocky Linux security update.
A vulnerability addressed by the Miracle Linux 9 AXSA-2026-1945 update for GDB-related packages. The supplied information rates it as high impact to confidentiality, integrity, and availability under CVSS v3, while requiring user interaction and high attack complexity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.