CVE-2026-90803 Overview
CVE-2026-90803 is a heap buffer overflow vulnerability in GNU Binutils 2.47, specifically affecting the elf_x86_64_relocate_section function in bfd/elf64-x86-64.c within the ld linker component. A malformed relocation entry allows an attacker to trigger an out-of-bounds read/write and a segmentation fault by manipulating the roff argument. The issue is classified under [CWE-119] (improper restriction of operations within the bounds of a memory buffer) and requires local access to exploit. GNU addressed the flaw in Binutils 2.48 through commit 471130b39c03623ec6d78ece377ff4da3f6bfe7b. The exploit has been publicly disclosed.
Critical Impact
Local attackers can trigger a heap out-of-bounds read/write and process crash in the GNU linker when it processes a maliciously crafted ELF object file.
Affected Products
- GNU Binutils 2.47
- GNU ld linker component (bfd/elf64-x86-64.c)
- Toolchains and build systems that link untrusted ELF object files using the affected Binutils release
Discovery Timeline
- 2026-09-14 - CVE-2026-90803 published to the National Vulnerability Database
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-90803
Vulnerability Analysis
The flaw resides in elf_x86_64_relocate_section, the routine responsible for applying x86-64 ELF relocations during linking. When the linker processes a malformed relocation, the roff (relocation offset) argument is used to compute a memory location without adequate bounds validation against the target section. The resulting memory access reads or writes outside the allocated heap buffer, producing a segmentation fault and potential heap corruption.
Because the defect is reached through the linker's handling of ELF input, any workflow that invokes ld on attacker-supplied object files exposes the vulnerable code path. The impact is bounded by local attack requirements and limited confidentiality, integrity, and availability effects on the linker process. However, in continuous integration pipelines that build untrusted source or object contributions, the vulnerability can be reached repeatedly and reliably.
Root Cause
The root cause is missing or insufficient validation of the relocation offset (roff) before it is used to index into a section buffer inside elf_x86_64_relocate_section. The upstream fix in commit 471130b39c03623ec6d78ece377ff4da3f6bfe7b tightens boundary checks so the linker rejects or safely handles relocations whose offsets fall outside the target section. See the Sourceware commit reference and Sourceware Bug #34444 for the patch details.
Attack Vector
Exploitation requires local access and the ability to have the victim invoke ld on a crafted ELF object. A public proof-of-concept demonstrates the heap out-of-bounds read/write and SEGV crash, documented in the GitHub write-up by r1ck9-2q. The vulnerability is triggered by malformed relocation records that reference offsets outside the intended section bounds; no elevated privileges or user interaction beyond running the linker are required.
Detection Methods for CVE-2026-90803
Indicators of Compromise
- Unexpected SIGSEGV termination of the ld process during builds involving third-party or untrusted object files.
- Presence of ELF .o files with relocation entries whose r_offset exceeds the size of the referenced section.
- Build pipeline logs showing repeated linker crashes tied to specific input objects.
Detection Strategies
- Query installed Binutils versions across build hosts and developer workstations, flagging any instance reporting 2.47.
- Run ELF validators (for example, readelf -r combined with section-size cross-checks) against object files ingested from external sources.
- Enable core-dump collection on build agents so linker crashes can be triaged rather than silently retried.
Monitoring Recommendations
- Alert on abnormal exit codes from ld in CI/CD job telemetry and correlate with the input artifacts being linked.
- Monitor package inventories for downgrade or pinning to Binutils 2.47 after the 2.48 upgrade is deployed.
- Track access to build systems that compile untrusted contributor code to constrain who can supply object files to the linker.
How to Mitigate CVE-2026-90803
Immediate Actions Required
- Upgrade GNU Binutils to version 2.48 or later on all build servers, CI runners, and developer workstations.
- Audit CI/CD pipelines that link externally supplied ELF objects and quarantine untrusted inputs until the upgrade is complete.
- Restrict local access to shared build hosts so only authorized users can invoke the linker against arbitrary object files.
Patch Information
The vulnerability is fixed in GNU Binutils 2.48. The corrective change is upstream commit 471130b39c03623ec6d78ece377ff4da3f6bfe7b, referenced in the Sourceware git tree and tracked in Sourceware Bug #34444. Distribution maintainers should backport this commit to any long-term-support Binutils 2.47 packages.
Workarounds
- Do not link ELF object files originating from untrusted sources on hosts still running Binutils 2.47.
- Use container-based build isolation so a linker crash cannot affect other tenants or persist on the host.
- Where upgrading immediately is impractical, apply the upstream patch 471130b39c03623ec6d78ece377ff4da3f6bfe7b to the local Binutils 2.47 source tree and rebuild.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.