cbcvebase.
CVE-2025-11840
published 2025-10-16

CVE-2025-11840: A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to…

PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.2th percentile
A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.46-1 (forky)binutils 2.46-1 (forky)
gnubinutils
gnubinutils>= 0 < 2.46-12.46-1
gnubinutils>= 0 < 2.38-4ubuntu2.112.38-4ubuntu2.11
gnubinutils>= 0 < 2.42-4ubuntu2.72.42-4ubuntu2.7
gnubinutils>= 0 < 2.45-7ubuntu1.12.45-7ubuntu1.1
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm72.24-5ubuntu14.2+esm7
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm132.26.1-1ubuntu1~16.04.8+esm13
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm52.30-21ubuntu1~18.04.9+esm5
gnubinutils>= 0 < 2.34-6ubuntu1.11+esm12.34-6ubuntu1.11+esm1
msrcazl3_binutils_2.41-9_on_azure_linux_3.0
msrccbl2_binutils_2.37-17_on_cbl_mariner_2.0
msrccbl2_binutils_2.37-19_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
vendor_msrc3.3LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.