CVE-2026-3442 is an out-of-bounds read described as a heap-based buffer overflow in the GNU Binutils bfd linker component. The flaw is triggered while processing a specially crafted malicious XCOFF object file.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small local proof-of-concept for a GNU Binutils/BFD out-of-bounds read vulnerability identified as CVE-2026-3442. The main file, CVE-2026-3442.c, is a standalone C program that constructs malformed ELF relocatable object files in memory and writes them to disk. Its core capability is crafting malicious section headers, symbol tables, string tables, and especially a .rela.text relocation section containing attacker-controlled relocation entries intended to drive Binutils into unsafe relocation parsing. After generating the files, the program tests them with local Binutils utilities, including readelf, objdump, and most importantly ld -r, which is presented as the vulnerable operation likely to trigger a crash or invalid read. Repository structure is minimal: README.md is only a placeholder, CVE-2026-3442.c contains the actual PoC logic, and build.sh automates compilation and execution. The shell script builds normal, debug, and optionally ASAN-instrumented binaries, runs the PoC, and optionally executes it under Valgrind while saving output to valgrind_full.log. This makes the repository useful for vulnerability reproduction and local validation rather than remote exploitation. There are no network endpoints, C2 addresses, or remote targets in the code. All observables are local file paths and local command invocations. The attack vector is local file-format exploitation: a victim or analyst processes a crafted ELF object with vulnerable Binutils tooling. The exploit does not deliver code execution payloads, persistence, or post-exploitation actions; it is focused on demonstrating memory-safety failure in Binutils. One notable inconsistency is that the banner and build script reference CVE-2024-2511 while the filename and README reference CVE-2026-3442, suggesting the PoC may have been adapted from an earlier example or contains copy/paste artifacts. Despite that inconsistency, the code behavior clearly aligns with a malformed-ELF OOB-read proof of concept targeting GNU Binutils.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by the referenced TuxCare CentOS 6 security advisory; no technical flaw description is provided.
A locally exploitable vulnerability requiring user interaction, with high confidentiality and availability impact according to the supplied CVSS v3 vector. It is addressed by a TuxCare security advisory for CentOS 7.
A vulnerability addressed by the referenced TuxCare CentOS 8 security update; no technical details are supplied.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.