CVE-2025-11081
published 2025-09-27CVE-2025-11081: A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation…
low1.9CVSS 4.0
AVLACLATNPRLUINVCNVINVALSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.46-1 (forky) | binutils 2.46-1 (forky) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.46-1 | 2.46-1 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.12 | 2.38-4ubuntu2.12 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.8 | 2.42-4ubuntu2.8 |
| gnu | binutils | >= 0 < 2.45-7ubuntu1.2 | 2.45-7ubuntu1.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm8 | 2.24-5ubuntu14.2+esm8 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm14 | 2.26.1-1ubuntu1~16.04.8+esm14 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm13 | 2.30-21ubuntu1~18.04.9+esm13 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.11+esm2 | 2.34-6ubuntu1.11+esm2 |
| msrc | azl3_binutils_2.41-7_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-16_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.8MEDIUM