cbcvebase.
CVE-2025-11082
published 2025-09-27

CVE-2025-11082: A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing…

low1.9CVSS 4.0
AVLACLATNPRLUINVCLVILVALSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

Affected

24 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.46-1 (forky)binutils 2.46-1 (forky)
gnubinutils
gnubinutils>= 0 < 2.46-12.46-1
gnubinutils>= 0 < 2.38-4ubuntu2.102.38-4ubuntu2.10
gnubinutils>= 0 < 2.38-4ubuntu2.122.38-4ubuntu2.12
gnubinutils>= 0 < 2.42-4ubuntu2.62.42-4ubuntu2.6
gnubinutils>= 0 < 2.42-4ubuntu2.82.42-4ubuntu2.8
gnubinutils>= 0 < 2.45-7ubuntu1.22.45-7ubuntu1.2
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm82.24-5ubuntu14.2+esm8
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm142.26.1-1ubuntu1~16.04.8+esm14
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm132.30-21ubuntu1~18.04.9+esm13
gnubinutils>= 0 < 2.34-6ubuntu1.11+esm22.34-6ubuntu1.11+esm2
msrcazl3_binutils_2.41-7_on_azure_linux_3.0
msrcazl3_binutils_2.41-9_on_azure_linux_3.0
msrcazl3_crash_8.0.4-4_on_azure_linux_3.0
msrcazl3_gdb_13.2-5_on_azure_linux_3.0
msrcazl3_gdb_13.2-6_on_azure_linux_3.0
msrccbl2_binutils_2.37-16_on_cbl_mariner_2.0
msrccbl2_binutils_2.37-17_on_cbl_mariner_2.0
msrccbl2_binutils_2.37-19_on_cbl_mariner_2.0
msrccbl2_crash_8.0.1-4_on_cbl_mariner_2.0
msrccbl2_gdb_11.2-10_on_cbl_mariner_2.0
msrccbl2_gdb_11.2-6_on_cbl_mariner_2.0
msrccbl2_gdb_11.2-7_on_cbl_mariner_2.0

CVSS provenance

nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.8MEDIUM