CVE-2025-1178Improper Restriction of Operations within the Bounds of a Memory Buffer in Binutils

Severity
6.3MEDIUMNVD
EPSS
0.1%
top 69.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11
Latest updateApr 7

Description

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recomm

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages3 packages

Debiangnu/binutils< 2.45-3
CVEListV5gnu/binutils2.43
NVDgnu/binutils2.43

🔴Vulnerability Details

4
OSV
binutils vulnerabilities2025-04-07
GHSA
GHSA-6cwx-2fwm-4jvm: A vulnerability was found in GNU Binutils 22025-02-11
OSV
CVE-2025-1178: A vulnerability was found in GNU Binutils 22025-02-11
CVEList
GNU Binutils ld libbfd.c bfd_putl64 memory corruption2025-02-11

📋Vendor Advisories

4
Ubuntu
GNU binutils vulnerabilities2025-04-07
Red Hat
binutils: GNU Binutils ld libbfd.c bfd_putl64 memory corruption2025-02-11
Microsoft
GNU Binutils ld libbfd.c bfd_putl64 memory corruption2025-02-11
Debian
CVE-2025-1178: binutils - A vulnerability was found in GNU Binutils 2.43. It has been declared as problema...2025
CVE-2025-1178 — GNU Binutils vulnerability | cvebase