cbcvebase.
CVE-2025-3198
published 2025-04-04

CVE-2025-3198: A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.7th percentile
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.45-3 (forky)binutils 2.45-3 (forky)
gnubinutils
gnubinutils
gnubinutils>= 0 < 2.45-32.45-3
gnubinutils>= 0 < 2.38-4ubuntu2.102.38-4ubuntu2.10
gnubinutils>= 0 < 2.38-4ubuntu2.112.38-4ubuntu2.11
gnubinutils>= 0 < 2.42-4ubuntu2.62.42-4ubuntu2.6
gnubinutils>= 0 < 2.42-4ubuntu2.72.42-4ubuntu2.7
gnubinutils>= 0 < 2.45-7ubuntu1.12.45-7ubuntu1.1
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm72.24-5ubuntu14.2+esm7
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm132.26.1-1ubuntu1~16.04.8+esm13
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm52.30-21ubuntu1~18.04.9+esm5
gnubinutils>= 0 < 2.34-6ubuntu1.11+esm12.34-6ubuntu1.11+esm1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.