CVE-2025-11494
published 2025-10-08CVE-2025-11494: A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker…
low1.9CVSS 4.0
AVLACLATNPRLUINVCNVINVALSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.46-1 (forky) | binutils 2.46-1 (forky) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.46-1 | 2.46-1 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.12 | 2.38-4ubuntu2.12 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.8 | 2.42-4ubuntu2.8 |
| gnu | binutils | >= 0 < 2.45-7ubuntu1.2 | 2.45-7ubuntu1.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm8 | 2.24-5ubuntu14.2+esm8 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm14 | 2.26.1-1ubuntu1~16.04.8+esm14 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm13 | 2.30-21ubuntu1~18.04.9+esm13 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.11+esm2 | 2.34-6ubuntu1.11+esm2 |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_crash_8.0.4-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-19_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_crash_8.0.1-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gdb_11.2-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-11_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.8MEDIUM