Out-of-Bounds Affecting mold package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-MOLD-15562036
  • published14 Mar 2026
  • disclosed12 Mar 2026

Introduced: 12 Mar 2026

CVE-2026-3994  (opens in a new tab)
CWE-119  (opens in a new tab)
CWE-122  (opens in a new tab)

How to fix?

There is no fixed version for Debian:unstable mold.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mold package and not the mold package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Base Scores

version 3.1