CVE-2023-25585
published 2023-09-14CVE-2023-25585: A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.38%
29.9th percentile
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.39.50.20221224-1 (bookworm) | binutils 2.39.50.20221224-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9 | 2.30-21ubuntu1~18.04.9 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.5 | 2.34-6ubuntu1.5 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.2 | 2.38-4ubuntu2.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm1 | 2.24-5ubuntu14.2+esm1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm6 | 2.26.1-1ubuntu1~16.04.8+esm6 |
| msrc | azl3_crash_8.0.4-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7LOW
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-25585: A flaw was found in Binutils
osv·2023-09-14·CVSS 5.5
CVE-2023-25585 [MEDIUM] CVE-2023-25585: A flaw was found in Binutils
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
GHSA
GHSA-7787-4vjc-4737: A flaw was found in Binutils
ghsa_unreviewed·2023-09-14
CVE-2023-25585 [MEDIUM] CWE-908 GHSA-7787-4vjc-4737: A flaw was found in Binutils
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
OSV
binutils vulnerabilities
osv·2023-05-24·CVSS 7.8
CVE-2023-1579 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive information. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 2
Microsoft
Field `file_table` of `struct module *module` is uninitialized
vendor_msrc·2023-09-12·CVSS 4.7
CVE-2023-25585 [MEDIUM] CWE-457 Field `file_table` of `struct module *module` is uninitialized
Field `file_table` of `struct module *module` is uninitialized
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-05-24·CVSS 7.8
CVE-2023-1972 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive informati
Debian
CVE-2023-25585: binutils - A flaw was found in Binutils. The use of an uninitialized field in the struct mo...
vendor_debian·2023·CVSS 4.7
CVE-2023-25585 [MEDIUM] CVE-2023-25585: binutils - A flaw was found in Binutils. The use of an uninitialized field in the struct mo...
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
Scope: local
bookworm: resolved (fixed in 2.39.50.20221224-1)
bullseye: open
forky: resolved (fixed in 2.39.50.20221224-1)
sid: resolved (fixed in 2.39.50.20221224-1)
trixie: resolved (fixed in 2.39.50.20221224-1)
Red Hat
binutils: Field `file_table` of `struct module *module` is uninitialized
vendor_redhat·2022-12-12·CVSS 4.7
CVE-2023-25585 [MEDIUM] CWE-457 binutils: Field `file_table` of `struct module *module` is uninitialized
binutils: Field `file_table` of `struct module *module` is uninitialized
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
Statement: This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this out-of-bounds read is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with addr2line. Furthermore, binutils does not handle privileg
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2023-25585https://bugzilla.redhat.com/show_bug.cgi?id=2167498https://security.netapp.com/advisory/ntap-20231103-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=29892https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=65cf035b8dc1df5d8020e0b1449514a3c42933e7https://access.redhat.com/security/cve/CVE-2023-25585https://bugzilla.redhat.com/show_bug.cgi?id=2167498https://security.netapp.com/advisory/ntap-20231103-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=29892https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=65cf035b8dc1df5d8020e0b1449514a3c42933e7
2023-09-14
Published