CVE-2025-3198
published 2025-04-04CVE-2025-3198: A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.7th percentile
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.45-3 (forky) | binutils 2.45-3 (forky) |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.45-3 | 2.45-3 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.10 | 2.38-4ubuntu2.10 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.11 | 2.38-4ubuntu2.11 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.6 | 2.42-4ubuntu2.6 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.7 | 2.42-4ubuntu2.7 |
| gnu | binutils | >= 0 < 2.45-7ubuntu1.1 | 2.45-7ubuntu1.1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm7 | 2.24-5ubuntu14.2+esm7 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm13 | 2.26.1-1ubuntu1~16.04.8+esm13 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm5 | 2.30-21ubuntu1~18.04.9+esm5 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.11+esm1 | 2.34-6ubuntu1.11+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-12-01·CVSS 3.1
CVE-2025-3198 [LOW] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils could be forced to perform an out-
of-bounds read in certain instances. An attacker with local access to
a system could possibly use this issue to cause a denial of service.
(CVE-2025-11839, CVE-2025-11840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2025-8225)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 14.04
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-10-29·CVSS 5.3
CVE-2025-11083 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. The attack is restricted to local execution.
(CVE-2025-11082)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2025-11083, CVE-2025-5244, CVE-2025-5245,
CVE-2025-7554)
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause crash, execute
arbitrary code or expose sensitive information. (CVE-2025-1147)
It was discovered that GNU binutils incorrectly handled ce
Red Hat
binutils: GNU Binutils objdump bucomm.c display_info memory leak
vendor_redhat·2025-04-04·CVSS 4.8
CVE-2025-3198 [MEDIUM] CWE-772 binutils: GNU Binutils objdump bucomm.c display_info memory leak
binutils: GNU Binutils objdump bucomm.c display_info memory leak
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
A flaw was found in GNU Binutils. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally.
Statement: This vulnerability is rated Low
Debian
CVE-2025-3198: binutils - A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as probl...
vendor_debian·2025·CVSS 4.8
CVE-2025-3198 [MEDIUM] CVE-2025-3198: binutils - A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as probl...
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.45-3)
sid: resolved (fixed in 2.45-3)
trixie: open
OSV
binutils vulnerabilities
osv·2025-12-01·CVSS 2.3
CVE-2025-11839 [LOW] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils could be forced to perform an out-
of-bounds read in certain instances. An attacker with local access to
a system could possibly use this issue to cause a denial of service.
(CVE-2025-11839, CVE-2025-11840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2025-8225)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2025
OSV
binutils vulnerabilities
osv·2025-10-29·CVSS 4.8
CVE-2025-11082 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. The attack is restricted to local execution.
(CVE-2025-11082)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2025-11083, CVE-2025-5244, CVE-2025-5245,
CVE-2025-7554)
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause crash, execute
arbitrary code or expose sensitive information. (CVE-2025-1147)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial
GHSA
GHSA-4m4r-j72q-7w52: A vulnerability has been found in GNU Binutils 2
ghsa_unreviewed·2025-04-04
CVE-2025-3198 [MEDIUM] CWE-401 GHSA-4m4r-j72q-7w52: A vulnerability has been found in GNU Binutils 2
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
OSV
CVE-2025-3198: A vulnerability has been found in GNU Binutils 2
osv·2025-04-04·CVSS 4.8
CVE-2025-3198 [MEDIUM] CVE-2025-3198: A vulnerability has been found in GNU Binutils 2
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
No detection rules found.
No public exploits indexed.
https://sourceware.org/bugzilla/show_bug.cgi?id=32716https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344dhttps://vuldb.com/?ctiid.303151https://vuldb.com/?id.303151https://vuldb.com/?submit.545773https://www.gnu.org/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=32716
2025-04-04
Published