Report
binutils insecure temp creation uses mktemp() fallback
da6e30da-c944-44e4-8a35-4c07a6edef38
In binutils/bucomm.c, make_tempname() and make_tempdir() use mktemp() when mkstemp()/mkdtemp() are unavailable. mktemp() only returns a name (no atomic creation), leaving a race window where an attacker can pre-create or symlink the chosen path before open()/mkdir() occurs (TOCTOU).