{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-18220",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.8,
   "affects": [
    "binutils"
   ],
   "title": "An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-18220"
  },
  {
   "id": "CVE-2026-6846",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.8,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking.",
   "url": "https://ubuntu.com/security/CVE-2026-6846"
  },
  {
   "id": "CVE-2025-66862",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "binutils"
   ],
   "title": "A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66862"
  },
  {
   "id": "CVE-2025-66863",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "binutils"
   ],
   "title": "An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66863"
  },
  {
   "id": "CVE-2025-66864",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "binutils"
   ],
   "title": "An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66864"
  },
  {
   "id": "CVE-2025-66865",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "binutils"
   ],
   "title": "An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66865"
  },
  {
   "id": "CVE-2025-66866",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "binutils"
   ],
   "title": "An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66866"
  },
  {
   "id": "CVE-2026-3441",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.1,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information.",
   "url": "https://ubuntu.com/security/CVE-2026-3441"
  },
  {
   "id": "CVE-2026-3442",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.1,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component.",
   "url": "https://ubuntu.com/security/CVE-2026-3442"
  },
  {
   "id": "CVE-2026-4647",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.1,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables.",
   "url": "https://ubuntu.com/security/CVE-2026-4647"
  },
  {
   "id": "CVE-2026-15003",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.6,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file.",
   "url": "https://ubuntu.com/security/CVE-2026-15003"
  },
  {
   "id": "CVE-2017-13716",
   "severity": "medium",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "binutils"
   ],
   "title": "The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated\u2026",
   "url": "https://ubuntu.com/security/CVE-2017-13716"
  },
  {
   "id": "CVE-2026-19548",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "binutils"
   ],
   "title": "Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils.",
   "url": "https://ubuntu.com/security/CVE-2026-19548"
  },
  {
   "id": "CVE-2026-6844",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file.",
   "url": "https://ubuntu.com/security/CVE-2026-6844"
  },
  {
   "id": "CVE-2026-6845",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.0,
   "affects": [
    "binutils"
   ],
   "title": "A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-6845"
  },
  {
   "id": "CVE-2025-1150",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 3.1,
   "affects": [
    "binutils"
   ],
   "title": "A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak.",
   "url": "https://ubuntu.com/security/CVE-2025-1150"
  },
  {
   "id": "CVE-2025-66861",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 2.5,
   "affects": [
    "binutils"
   ],
   "title": "An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.",
   "url": "https://ubuntu.com/security/CVE-2025-66861"
  },
  {
   "id": "CVE-2025-1151",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 2.3,
   "affects": [
    "binutils"
   ],
   "title": "A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak.",
   "url": "https://ubuntu.com/security/CVE-2025-1151"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 9,
  "medium": 6,
  "low": 3,
  "unknown": 0
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  }
 ]
}
