What is CVE-2026-56390?
CVE-2026-56390 affects GNU Bison where grammar directives like %output allow arbitrary file paths. When processing attacker-supplied grammar, this can redirect output to unintended files, potentially enabling code execution.
Azərbaycanca: CVE-2026-56390 GNU Bison-da tapılıb. Təhlükəli qrammatika faylları %output direktivi vasitəsilə ixtiyari fayl yolu təyin edə bilər. Bu, xüsusi qrammatika emal edərkən fayl yazma əməliyyatlarını yönləndirərək kod yeridilməsinə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
How can CVE-2026-56390 be exploited?
Malicious grammar files can specify arbitrary file paths via the %output directive. When processing attacker-supplied grammar, this can redirect file write operations, potentially enabling code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.