← All Advisories

CVE-2026-13732

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-13732

Key Details

CVECVE-2026-13732
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-10-09
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Hardened Images
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Cost Management On-Premise 1
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in GDB's STABS debug format parser. The

read_member_functions() function in gdb/stabsread.c contains a linked

list removal bug in the code that separates destructor and non-destructor

member functions of C++ classes. The bug causes the destructor entries to

remain in the main function list while the list length counter is

decremented, resulting in an out-of-bounds write when the function list

is copied to its final allocated array. An attacker can craft an ELF

binary with malicious .stab and .stabstr sections that triggers this

out-of-bounds write when a user opens the file in GDB and performs any

symbol-inspection operation such as setting a breakpoint. The inferior

process does not need to be executed. Under controlled conditions, this

was demonstrated to achieve execution of arbitrary commands within the

GDB process. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-13732
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-13732