CVE-2026-6844
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.
- Affected products
- Binutils
- Gnu Binutils
- All versions
- Redhat Hardened Images
- All versions
- Redhat Openshift Container Platform
- = 4.0
- Redhat Enterprise Linux
- = 7.0, 8.0, 9.0, 10.0
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.1% (1th percentile)
- Weakness
- CWE-400
- NVD status
- Analyzed
- Published
- 2026-04-22
Workaround
To mitigate this vulnerability, users should avoid using the `readelf` utility on untrusted or suspicious ELF files. Processing a specially crafted ELF file with `readelf` can lead to a denial of service.
No indexed exploits for CVE-2026-6844 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-6844 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.