7

CVE-2026-13732

Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf

A flaw was found in GDB's STABS debug format parser. The
read_member_functions() function in gdb/stabsread.c contains a linked
list removal bug in the code that separates destructor and non-destructor
member functions of C++ classes. The bug causes the destructor entries to
remain in the main function list while the list length counter is
decremented, resulting in an out-of-bounds write when the function list
is copied to its final allocated array. An attacker can craft an ELF
binary with malicious .stab and .stabstr sections that triggers this
out-of-bounds write when a user opens the file in GDB and performs any
symbol-inspection operation such as setting a breakpoint. The inferior
process does not need to be executed. Under controlled conditions, this
was demonstrated to achieve execution of arbitrary commands within the
GDB process.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
Version 0:16.3-3.1.el10_2
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
Version 0:8.2-20.1.el8_10
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
Version 0:16.3-3.1.el9_8
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 6
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Hardened Images
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/security/cve/CVE-2026-13732
https://bugzilla.redhat.com/show_bug.cgi?id=2494416
https://access.redhat.com/errata/RHSA-2026:73425
https://access.redhat.com/errata/RHSA-2026:73427
https://access.redhat.com/errata/RHSA-2026:73426