cbcvebase.
CVE-2025-11494
published 2025-10-08

CVE-2025-11494: A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.9th percentile
A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.46-1 (forky)binutils 2.46-1 (forky)
gnubinutils
gnubinutils>= 0 < 2.46-12.46-1
gnubinutils>= 0 < 2.38-4ubuntu2.122.38-4ubuntu2.12
gnubinutils>= 0 < 2.42-4ubuntu2.82.42-4ubuntu2.8
gnubinutils>= 0 < 2.45-7ubuntu1.22.45-7ubuntu1.2
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm82.24-5ubuntu14.2+esm8
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm142.26.1-1ubuntu1~16.04.8+esm14
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm132.30-21ubuntu1~18.04.9+esm13
gnubinutils>= 0 < 2.34-6ubuntu1.11+esm22.34-6ubuntu1.11+esm2
msrcazl3_binutils_2.41-10_on_azure_linux_3.0
msrcazl3_crash_8.0.4-5_on_azure_linux_3.0
msrccbl2_binutils_2.37-19_on_cbl_mariner_2.0
msrccbl2_crash_8.0.1-5_on_cbl_mariner_2.0
msrccbl2_gdb_11.2-10_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-11_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
vendor_msrc4.4MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.