SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90801

MEDIUM · CVSS 5.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A buffer overflow vulnerability exists in the cache_bwrite function of GNU Binutils 2.47, allowing local attackers to manipulate the nbytes argument. This flaw could lead to potential code execution or system instability. Organizations using this version of GNU Binutils should prioritize patching to mitigate the risk of exploitation, especially in environments where local access is possible.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90801
Severity
MEDIUM
CVSS
5.3
EPSS
N/A

Original NVD Description

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.