RFC: Fix for CVE-2026-19548
Hans-Peter Nilsson
hp@bitrange.com
Mon Aug 17 14:24:34 GMT 2026
On Mon, 17 Aug 2026, Nick Clifton wrote:
> Hi Alan,
>
> > The bug report says:
> > "The vulnerability is triggered when LTO plugins are active
> > (link_info.lto_plugin_active is true) and the input object has
> > abfd->my_archive == NULL"
> >
> > If my_archive is NULL the bfd isn't an archive member!
>
> True - I suspect that this is a theoretical bug, rather than an exploitable
> one.
>
> > How is it that add_archive_element is being called for something that
> > isn't a member of an archive? Do you have a testcase?
>
> No - I was just responding to the CVE - which does not provide a testcase.
> Cheers
> Nick
Does that mean that the binutils CVE process has an exploitable
flaw in which an opponent can DOS developers with red herring
CVEs? 1/2 :-)
brgds, H-P
More information about the Binutils
mailing list