CVE-2026-90801 Overview
CVE-2026-90801 is a heap buffer overflow vulnerability in GNU Binutils 2.47. The flaw resides in the cache_bwrite function in bfd/cache.c, part of the ld linker component. Attackers manipulate the nbytes argument to trigger the overflow when processing a malformed ELF file with --gc-sections -w flags. Exploitation requires local access and low privileges. Public exploit details have been released through a GitHub proof-of-concept repository. The GNU project was notified via a Sourceware bug report but has not yet responded. The vulnerability is classified under [CWE-119] (Improper Restriction of Operations within the Bounds of a Memory Buffer).
Critical Impact
Local attackers can trigger a heap buffer overflow in the GNU linker by supplying a malformed ELF object, potentially corrupting heap memory during linking operations.
Affected Products
- GNU Binutils 2.47
- ld linker component
- bfd/cache.c — cache_bwrite function
Discovery Timeline
- 2026-09-14 - CVE-2026-90801 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-90801
Vulnerability Analysis
The vulnerability exists in the cache_bwrite function located at bfd/cache.c:436 within the Binary File Descriptor (BFD) library used by the GNU linker. When ld processes a specially crafted ELF file with the --gc-sections and -w options, the nbytes parameter passed to cache_bwrite is not properly validated against the destination heap buffer size. This mismatch allows write operations to exceed the allocated buffer, resulting in a heap-based buffer overflow.
Exploitation is limited to local attack vectors and requires the target system or user to invoke ld against attacker-controlled input. The overflow can corrupt adjacent heap metadata, which may lead to process crashes or, under specific memory layout conditions, altered control flow within the linker process.
Root Cause
The root cause is missing bounds validation on the nbytes argument in cache_bwrite. The BFD cache write path assumes the caller has provided a size that fits within the underlying cached buffer. A malformed ELF section header can cause the linker to compute an unsafe size, allowing data to be written past the buffer boundary.
Attack Vector
An attacker crafts a malformed ELF object file and delivers it to a target user or automated build pipeline. When the linker processes the file with ld --gc-sections -w <malicious.o>, the overflow triggers. The attack surface is therefore limited to systems where untrusted object files are linked, such as CI/CD systems, shared build hosts, and multi-user development environments. See the Sourceware Bug Report for technical reproduction details.
No verified code example is publicly available in a form suitable for reproduction here. The published proof of concept is described in the GitHub PoC Repository.
Detection Methods for CVE-2026-90801
Indicators of Compromise
- Crashes or ASAN reports referencing cache_bwrite in bfd/cache.c during ld execution.
- Unexpected ld process terminations while processing third-party or untrusted object files.
- Presence of malformed ELF object files in build directories that trigger linker faults with --gc-sections -w.
Detection Strategies
- Run linker jobs under AddressSanitizer (ASAN) in test environments to surface heap overflows during ELF processing.
- Audit build systems for the installed Binutils version and flag hosts running version 2.47.
- Review CI/CD job logs for ld signal terminations (SIGABRT, SIGSEGV) correlated with --gc-sections invocations.
Monitoring Recommendations
- Monitor developer and build-server endpoints for anomalous ld process crashes and unexpected child-process behavior originating from build toolchains.
- Track file drops of unknown ELF objects into shared build directories through endpoint telemetry.
- Alert on invocation of ld against externally sourced object files in privileged contexts.
How to Mitigate CVE-2026-90801
Immediate Actions Required
- Inventory all systems running GNU Binutils 2.47 and identify those exposed to untrusted object files.
- Restrict linker execution on shared build hosts to trusted input sources until a patch is available.
- Enable compiler and linker hardening (-D_FORTIFY_SOURCE=2, ASLR, heap protections) on affected systems.
Patch Information
No vendor patch has been published at the time of writing. The GNU Binutils project has been notified through the Sourceware Bug Report but has not yet responded. Monitor the upstream Binutils release notes and the referenced bug tracker for a fix. Downgrading to a prior stable Binutils release that does not exhibit the flaw may be considered where feasible.
Workarounds
- Avoid invoking ld with the --gc-sections -w flag combination on untrusted object files.
- Sandbox linker execution in CI/CD pipelines using containers or restricted user accounts to contain any heap corruption impact.
- Validate the origin and integrity of all object files ingested into build systems before linking.
# Example: run ld inside a restricted, non-privileged sandbox
sudo -u builduser \
systemd-run --scope --uid=builduser --gid=builduser \
--property=NoNewPrivileges=yes \
--property=PrivateTmp=yes \
ld -o output.elf input.o
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.