{"id":"DEBIAN-CVE-2026-19548","details":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry-\u003ethe_bfd-\u003emy_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd-\u003emy_archive via bfd_usrdata(abfd-\u003emy_archive) 2. Line ~1493: multiple accesses to abfd and abfd-\u003emy_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd-\u003emy_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd-\u003emy_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","modified":"2026-09-14T17:02:50.535961889Z","published":"2026-08-12T16:16:55.777Z","upstream":["CVE-2026-19548"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-19548"}],"affected":[{"package":{"name":"binutils","ecosystem":"Debian:12","purl":"pkg:deb/debian/binutils?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.40-2","2.40.50.20230111-1","2.40.50.20230215-1","2.40.50.20230501-1","2.40.50.20230510-1","2.40.50.20230602-1","2.40.50.20230611-1","2.40.50.20230611-2","2.40.50.20230622-1","2.40.50.20230625-1","2.40.50.20230630-1","2.40.90.20230705-1","2.40.90.20230714-1","2.40.90.20230714-2","2.40.90.20230720-1","2.40.90.20230729-1","2.40.90.20230729-2","2.41-1","2.41-2","2.41-3","2.41-4","2.41-5","2.41-6","2.41-7","2.41.50.20230731-1","2.41.50.20230803-1","2.41.50.20230905-1","2.41.50.20231010-1","2.41.50.20231101-1","2.41.50.20231125-1","2.41.50.20231202-1","2.41.50.20231206-1","2.41.50.20231214-1","2.41.50.20231227-1","2.41.90.20240115-1","2.41.90.20240122-1","2.42-1","2.42-2","2.42-2+hurd.1","2.42-3","2.42-4","2.42.50.20240614-1","2.42.50.20240618-1","2.42.50.20240625-1","2.42.50.20240710-1","2.42.90.20240720-1","2.42.90.20240720-2","2.43-1","2.43-2","2.43.1-1","2.43.1-2","2.43.1-3","2.43.1-4","2.43.1-5","2.43.50.20240817-1","2.43.50.20240909-1","2.43.50.20241004-1","2.43.50.20241112-1","2.43.50.20241126-1","2.43.50.20241126-2","2.43.50.20241126-3","2.43.50.20241204-1","2.43.50.20241204-2","2.43.50.20241210-1","2.43.50.20241215-1","2.43.50.20241221-1","2.43.50.20241230-1","2.43.50.20250108-1","2.43.90.20250122-1","2.43.90.20250122-2","2.43.90.20250127-1","2.43.90.20250202-1","2.44-1","2.44-2","2.44-3","2.44.50.20250201-1","2.44.50.20250207-1","2.44.50.20250218-1","2.44.50.20250218-2","2.44.50.20250309-1","2.44.50.20250405-1","2.44.50.20250502-1","2.44.50.20250520-1","2.44.50.20250528-1","2.44.50.20250707-1","2.44.90.20250719-1","2.45-1","2.45-2","2.45-3","2.45-4","2.45-5","2.45-6","2.45-7","2.45-8","2.45.50.20250813-1","2.45.50.20250903-1","2.45.50.20251005-1","2.45.50.20251023-1","2.45.50.20251023-2","2.45.50.20251122-1","2.45.50.20251125-1","2.45.50.20251201-1","2.45.50.20251209-1","2.45.50.20260116-1","2.45.50.20260119-1","2.45.90.20260125-1","2.45.90.20260201-1","2.46-1","2.46-2","2.46-3","2.46.50.20260216-1","2.46.50.20260509-1","2.46.50.20260519-1","2.46.50.20260608-1","2.46.50.20260617-1","2.46.90.20260712-1","2.47-1","2.47-2","2.47-3","2.47-4","2.47-5","2.47-6","2.47.50.20260813-1","2.47.50.20260813-2","2.47.50.20260813-3","2.47.50.20260901-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19548.json"}},{"package":{"name":"binutils","ecosystem":"Debian:13","purl":"pkg:deb/debian/binutils?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.44-3","2.44.50.20250201-1","2.44.50.20250207-1","2.44.50.20250218-1","2.44.50.20250218-2","2.44.50.20250309-1","2.44.50.20250405-1","2.44.50.20250502-1","2.44.50.20250520-1","2.44.50.20250528-1","2.44.50.20250707-1","2.44.90.20250719-1","2.45-1","2.45-2","2.45-3","2.45-4","2.45-5","2.45-6","2.45-7","2.45-8","2.45.50.20250813-1","2.45.50.20250903-1","2.45.50.20251005-1","2.45.50.20251023-1","2.45.50.20251023-2","2.45.50.20251122-1","2.45.50.20251125-1","2.45.50.20251201-1","2.45.50.20251209-1","2.45.50.20260116-1","2.45.50.20260119-1","2.45.90.20260125-1","2.45.90.20260201-1","2.46-1","2.46-2","2.46-3","2.46.50.20260216-1","2.46.50.20260509-1","2.46.50.20260519-1","2.46.50.20260608-1","2.46.50.20260617-1","2.46.90.20260712-1","2.47-1","2.47-2","2.47-3","2.47-4","2.47-5","2.47-6","2.47.50.20260813-1","2.47.50.20260813-2","2.47.50.20260813-3","2.47.50.20260901-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19548.json"}},{"package":{"name":"binutils","ecosystem":"Debian:14","purl":"pkg:deb/debian/binutils?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.44-3","2.44.50.20250201-1","2.44.50.20250207-1","2.44.50.20250218-1","2.44.50.20250218-2","2.44.50.20250309-1","2.44.50.20250405-1","2.44.50.20250502-1","2.44.50.20250520-1","2.44.50.20250528-1","2.44.50.20250707-1","2.44.90.20250719-1","2.45-1","2.45-2","2.45-3","2.45-4","2.45-5","2.45-6","2.45-7","2.45-8","2.45.50.20250813-1","2.45.50.20250903-1","2.45.50.20251005-1","2.45.50.20251023-1","2.45.50.20251023-2","2.45.50.20251122-1","2.45.50.20251125-1","2.45.50.20251201-1","2.45.50.20251209-1","2.45.50.20260116-1","2.45.50.20260119-1","2.45.90.20260125-1","2.45.90.20260201-1","2.46-1","2.46-2","2.46-3","2.46.50.20260216-1","2.46.50.20260509-1","2.46.50.20260519-1","2.46.50.20260608-1","2.46.50.20260617-1","2.46.90.20260712-1","2.47-1","2.47-2","2.47-3","2.47-4","2.47-5","2.47-6","2.47.50.20260813-1","2.47.50.20260813-2","2.47.50.20260813-3","2.47.50.20260901-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-19548.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}