{"id":"CVE-2026-3994","summary":"rui314 mold Object File input-files.cc initialize_sections heap-based overflow","details":"A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.","modified":"2026-08-12T03:51:30.676889066Z","published":"2026-03-12T06:02:11.026Z","database_specific":{"cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3994.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/rui314/mold/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3994.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3994"},{"type":"ADVISORY","url":"https://vuldb.com/?id.350476"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.769772"},{"type":"REPORT","url":"https://github.com/rui314/mold/issues/1548"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.350476"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0209/blob/main/mo2/repro"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rui314/mold","events":[{"introduced":"b53197300b5bf9f02daccae536f65dda2d1431c5"},{"last_affected":"083901f42dea2491be8bc7cf6e3b1e2b9a3c850d"}],"database_specific":{"extracted_events":[{"introduced":"2.40.0"},{"last_affected":"2.40.0"},{"introduced":"2.40.1"},{"last_affected":"2.40.1"},{"introduced":"2.40.2"},{"last_affected":"2.40.2"},{"introduced":"2.40.3"},{"last_affected":"2.40.3"},{"introduced":"2.40.4"},{"last_affected":"2.40.4"}],"source":"AFFECTED_FIELD"}}],"versions":["2.40.0","2.40.1","2.40.2","2.40.3","2.40.4","v2.40.4","v2.40.3","v2.40.2","v2.40.1","v2.40.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3994.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}