CVE-2025-1176
published 2025-02-11CVE-2025-1176: A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the…
PriorityP429medium5CVSS 3.1
AVNACHPRNUIRSUCLILAL
EPSS
0.66%
48.0th percentile
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.45-3 (forky) | binutils 2.45-3 (forky) |
| expressjs | multer | >= 1.4.4-lts.1 < 2.0.0 | 2.0.0 |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.45-3 | 2.45-3 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.11 | 2.34-6ubuntu1.11 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.8 | 2.38-4ubuntu2.8 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.5 | 2.42-4ubuntu2.5 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm11 | 2.26.1-1ubuntu1~16.04.8+esm11 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm4 | 2.30-21ubuntu1~18.04.9+esm4 |
| msrc | azl3_binutils_2.41-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_binutils_2.41-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_binutils_2.37-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gdb_11.2-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gdb_11.2-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-9_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv6.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d,
vendor_msrc·2025-09-09·CVSS 5.3
CVE-2025-46153 [MEDIUM] CWE-1176 PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d,
PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-04-29·CVSS 5.0
CVE-2025-1176 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-7423-1 fixed several vulnerabilities in GNU. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2025-0840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code.
(CVE-2025-1153)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to execute arbitrary
code. (CVE-202
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-04-07·CVSS 3.1
CVE-2025-1182 [LOW] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code.
(CVE-2025-1153, CVE-2025-1182)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2025-1176)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2025-1178, CVE-2025-1181)
Instructions:
Microsoft
GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
vendor_msrc·2025-02-11·CVSS 5.0
CVE-2025-1176 [LOW] CWE-122 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: h
Red Hat
binutils: GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
vendor_redhat·2025-02-11·CVSS 2.3
CVE-2025-1176 [LOW] CWE-787 binutils: GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
binutils: GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
A flaw was found in GNU Binutils. This vulnerability allows a heap-based buffer overflow via the _bfd_elf_gc_mark_rsec function.
Mitigation: Mitigation for this issue is either not available
Debian
CVE-2025-1176: binutils - A vulnerability was found in GNU Binutils 2.43 and classified as critical. This ...
vendor_debian·2025·CVSS 2.3
CVE-2025-1176 [LOW] CVE-2025-1176: binutils - A vulnerability was found in GNU Binutils 2.43 and classified as critical. This ...
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.45-3)
sid: resolved (fixed in 2.45-3)
trixie: open
GHSA
Multer vulnerable to Denial of Service from maliciously crafted requests
ghsa·2025-05-19
CVE-2025-47944 [HIGH] CWE-248 Multer vulnerable to Denial of Service from maliciously crafted requests
Multer vulnerable to Denial of Service from maliciously crafted requests
### Impact
A vulnerability in Multer versions >=1.4.4-lts.1 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process.
### Patches
Users should upgrade to `2.0.0`
### Workarounds
None
### References
- https://github.com/expressjs/multer/issues/1176
- https://github.com/expressjs/multer/commit/2c8505f207d923dd8de13a9f93a4563e59933665
OSV
binutils vulnerabilities
osv·2025-04-29·CVSS 6.3
CVE-2025-0840 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
USN-7423-1 fixed several vulnerabilities in GNU. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2025-0840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code.
(CVE-2025-1153)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2025-1176)
OSV
binutils vulnerabilities
osv·2025-04-07·CVSS 2.3
CVE-2025-1153 [LOW] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code.
(CVE-2025-1153, CVE-2025-1182)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2025-1176)
It was discovered that ld in GNU binutils incorrectly handled certain
files. An attacker could possibly use this issue to cause a crash, expose
sensitive information or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2025-1178, CVE-2025-1181)
GHSA
GHSA-9373-29x4-fjwq: A vulnerability was found in GNU Binutils 2
ghsa_unreviewed·2025-02-11
CVE-2025-1176 [LOW] CWE-119 GHSA-9373-29x4-fjwq: A vulnerability was found in GNU Binutils 2
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
OSV
CVE-2025-1176: A vulnerability was found in GNU Binutils 2
osv·2025-02-11·CVSS 2.3
CVE-2025-1176 [LOW] CVE-2025-1176: A vulnerability was found in GNU Binutils 2
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sourceware.org/bugzilla/attachment.cgi?id=15913https://sourceware.org/bugzilla/show_bug.cgi?id=32636https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814https://vuldb.com/?ctiid.295079https://vuldb.com/?id.295079https://vuldb.com/?submit.495329https://www.gnu.org/https://security.netapp.com/advisory/ntap-20250411-0007/
2025-02-11
Published