CVE-2026-18220 is an out-of-bounds write vulnerability in the GNU binutils BFD library's DLX ELF backend, specifically in bfd/elf32-dlx.c. The flaw is in dlx_rtype_to_howto(), which translates ELF relocation types into internal howto structures. The function does not adequately validate attacker-controlled relocation type values derived from ELF32_R_TYPE(r_info) before using them as indexes into dlx_elf_howto_table[]. Because the DLX relocation type namespace is non-contiguous, with ordinary values in a small low range and extended values in a high range, the default switch path can permit invalid relocation type values to reach the array access and cause memory corruption. A crafted ELF/DLX object file can trigger the vulnerability when processed by BFD-based utilities such as objdump, readelf, strip, ld, nm, or objcopy. The issue has been demonstrated as exploitable for arbitrary code execution through corruption of glibc FILE structures using a File Stream Oriented Programming technique.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working local file-based exploit for CVE-2026-18220 in GNU Binutils `objdump`, specifically the DLX relocation handler in `bfd/elf32-dlx.c`. Structure is minimal: `README.md` documents the bug, exploitation theory, reproduction steps, and patch; `poc_generate.py` builds a malicious ELF32 DLX relocatable object with a large `.debug_info` section and crafted `R_DLX_RELOC_26_PCREL` relocations; `poc_ptrace.py` is the main operational exploit that launches objdump, uses ptrace to resolve ASLR-dependent addresses at runtime, patches relocation symbol values, and retries automatically for reliability. The exploit capability is arbitrary code execution when a local user runs `objdump -g` on the crafted file. The primitive is an out-of-bounds 4-byte read/write caused by unchecked `reloc_entry->address` in `elf32_dlx_relocate26()`. The exploit turns this into FSOP by corrupting `_IO_2_1_stderr_` fields, planting fake `_IO_wide_data` and `_IO_jump_t` structures inside the mmap-backed section buffer, and redirecting the `__doallocate` slot to `system()`. When objdump later writes an error to stderr, the corrupted FILE object causes `system(stderr)` to execute an attacker-controlled short command embedded in `_flags`. `poc_generate.py` is the payload generator. It defines ELF/DLX constants, hardcoded profiled addresses for a non-ASLR environment, helpers for packing/building ELF structures, and logic to encode the required relocation writes and fake FILE-related structures into the output ELF. It supports `--cmd` and `-o/--out`, with command-length and bit-constraint validation. `poc_ptrace.py` is the runtime exploit wrapper. It expects a local vulnerable objdump build and generated payload, then attaches to the child process with ptrace, intercepts execution around `elf32_dlx_relocate26()`, computes actual libc/object addresses under ASLR, patches symbol values for the relocation entries, and continues execution until the FSOP chain triggers. This makes the exploit more reliable than the static payload alone and elevates the repository from a simple PoC to an operational exploit. No external network infrastructure, C2, or remote callback endpoints are present. The attack vector is local/file-based: delivery is a crafted ELF file processed by a vulnerable binary.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.