{"id":"UBUNTU-CVE-2026-13732","details":"A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.","modified":"2026-09-11T20:50:12.630125261Z","published":"2026-08-31T20:17:00Z","upstream":["CVE-2026-13732"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-13732"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-13732"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-13732"}],"affected":[{"package":{"name":"gdb","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=esm-infra%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.10-1ubuntu2","7.10-1ubuntu3","7.10.1-0ubuntu1","7.10.90.20160215-0ubuntu2","7.10.90.20160220-0ubuntu1","7.11-0ubuntu1","7.11.1-0ubuntu1~16.04","7.11.1-0ubuntu1~16.5","7.11.1-0ubuntu1~16.5+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"gdb","binary_version":"7.11.1-0ubuntu1~16.5+esm1"},{"binary_name":"gdb-multiarch","binary_version":"7.11.1-0ubuntu1~16.5+esm1"},{"binary_name":"gdb-source","binary_version":"7.11.1-0ubuntu1~16.5+esm1"},{"binary_name":"gdb64","binary_version":"7.11.1-0ubuntu1~16.5+esm1"},{"binary_name":"gdbserver","binary_version":"7.11.1-0ubuntu1~16.5+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}},{"package":{"name":"gdb","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.0.1-0ubuntu1","8.0.1-0ubuntu2","8.0.1-0ubuntu3","8.1-0ubuntu1","8.1-0ubuntu2","8.1-0ubuntu3","8.1-0ubuntu3.1","8.1-0ubuntu3.2","8.1.1-0ubuntu1","8.1.1-0ubuntu1+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"gdb","binary_version":"8.1.1-0ubuntu1+esm1"},{"binary_name":"gdb-multiarch","binary_version":"8.1.1-0ubuntu1+esm1"},{"binary_name":"gdb-source","binary_version":"8.1.1-0ubuntu1+esm1"},{"binary_name":"gdbserver","binary_version":"8.1.1-0ubuntu1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}},{"package":{"name":"gdb","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.3-0ubuntu1","9.0.50.20191019-0ubuntu1","9.0.50.20191119-0ubuntu1","9.0.90.20191216-0ubuntu1","9.0.90.20200105-0ubuntu1","9.0.90.20200117-0ubuntu1","9.1-0ubuntu1","9.2-0ubuntu1~20.04","9.2-0ubuntu1~20.04.1","9.2-0ubuntu1~20.04.2"],"ecosystem_specific":{"binaries":[{"binary_version":"9.2-0ubuntu1~20.04.2","binary_name":"gdb"},{"binary_name":"gdb-multiarch","binary_version":"9.2-0ubuntu1~20.04.2"},{"binary_version":"9.2-0ubuntu1~20.04.2","binary_name":"gdb-source"},{"binary_name":"gdbserver","binary_version":"9.2-0ubuntu1~20.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}},{"package":{"name":"gdb","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["11.1-0ubuntu2","11.1-0ubuntu3","11.2-0ubuntu1","12.0.50.20220217-0ubuntu1","12.0.90-0ubuntu1","12.1-0ubuntu1~22.04","12.1-0ubuntu1~22.04.2"],"ecosystem_specific":{"binaries":[{"binary_version":"12.1-0ubuntu1~22.04.2","binary_name":"gdb"},{"binary_version":"12.1-0ubuntu1~22.04.2","binary_name":"gdb-multiarch"},{"binary_name":"gdb-source","binary_version":"12.1-0ubuntu1~22.04.2"},{"binary_name":"gdbserver","binary_version":"12.1-0ubuntu1~22.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}},{"package":{"name":"gdb","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["14.0.50.20230907-0ubuntu1","14.1-0ubuntu1","14.1-0ubuntu2","15.0.50.20240219-0ubuntu1","15.0.50.20240320-0ubuntu1","15.0.50.20240403-0ubuntu1","15.1-1ubuntu1~24.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"15.1-1ubuntu1~24.04.1","binary_name":"gdb"},{"binary_version":"15.1-1ubuntu1~24.04.1","binary_name":"gdb-multiarch"},{"binary_name":"gdb-source","binary_version":"15.1-1ubuntu1~24.04.1"},{"binary_name":"gdbserver","binary_version":"15.1-1ubuntu1~24.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}},{"package":{"name":"gdb","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/gdb?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["16.3-1ubuntu2","16.3-5ubuntu1","17.1-1ubuntu1","17.1-1ubuntu2","17.1-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"17.1-2ubuntu1","binary_name":"gdb"},{"binary_name":"gdb-minimal","binary_version":"17.1-2ubuntu1"},{"binary_name":"gdb-multiarch","binary_version":"17.1-2ubuntu1"},{"binary_name":"gdb-source","binary_version":"17.1-2ubuntu1"},{"binary_name":"gdbserver","binary_version":"17.1-2ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13732.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}