CVE-2026-3994: RUI314 Mold

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • RUI314 Mold: version 2.40.0 only; version 2.40.1 only; version 2.40.2 only; version 2.40.3 only; version 2.40.4 only

Published 2026-03-12. Last modified 2026-06-17.