Does commit c2bf7de1 fix CVE-2026-3441 and CVE-2026-3442?
Dora, Sunil Kumar
SunilKumar.Dora@windriver.com
Mon Jun 22 11:06:00 GMT 2026
Hi,
I'm looking at commit c2bf7de1eb7<https://sourceware.org/git/?p=binutils-gdb.git;a=patch;h=c2bf7de1eb77a91d7a3c86d56408bf57de540faf> <https://sourceware.org/git/?p=binutils-gdb.git;a=patch;h=c2bf7de1eb77a91d7a3c86d56408bf57de540faf> ("xcofflink buffer overflows") for a downstream update and want to tag it correctly.
The diff fixes two out-of-bounds reads in xcoff_link_add_symbols: the x_scnlen index check and the r_symndx check. That looks like it matches Red Hat's CVE-2026-3441<https://nvd.nist.gov/vuln/detail/CVE-2026-3441> and CVE-2026-3442<https://nvd.nist.gov/vuln/detail/CVE-2026-3442> (bugs 2443826 and 2443828).
Can someone confirm this commit is the fix for those two CVEs? And do the two hunks map to one CVE each, or do both CVEs cover the whole change?
Also, is this planned for the binutils-2_46-branch / a 2.46.2 release ?
And would it be OK if I send a backport request for this commit to binutils-2_46-branch?
Thanks,
Sunil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://sourceware.org/pipermail/binutils/attachments/20260622/b3a364eb/attachment.htm>
More information about the Binutils
mailing list