GNU binutils是美国GNU基金会开源的一套二进制工具集程序。 GNU Binutils存在缓冲区错误漏洞,该漏洞源于BFD库的DLX ELF后端(bfd/elf32-dlx.c)中dlx_rtype_to_howto()函数未能对攻击者控制的重定位类型值进行充分边界检查,可能导致越界写入,攻击者可构造特制ELF/DLX对象文件触发此漏洞,进而实现任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat Hardened Images | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18255 | 7.2 HIGH | Quay: quay: global read-only superuser can view robot account tokens |
| CVE-2026-18207 | 6.5 MEDIUM | Keycloak-services: keycloak-services: client policy source-group condition bypass via dupl |
| CVE-2026-18201 | 5.5 MEDIUM | Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers |
No comments yet