CVE-2025-5245
published 2025-05-27CVE-2025-5245: A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.5th percentile
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.45-3 (forky) | binutils 2.45-3 (forky) |
| gnu | binutils | < 2.45 | 2.45 |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
ghsa8.8HIGH
osv4.8MEDIUM
vendor_redhat7.9HIGH
vendor_msrc5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-12-01·CVSS 3.1
CVE-2025-3198 [LOW] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils could be forced to perform an out-
of-bounds read in certain instances. An attacker with local access to
a system could possibly use this issue to cause a denial of service.
(CVE-2025-11839, CVE-2025-11840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2025-8225)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 14.04
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-10-29·CVSS 5.3
CVE-2025-11083 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. The attack is restricted to local execution.
(CVE-2025-11082)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2025-11083, CVE-2025-5244, CVE-2025-5245,
CVE-2025-7554)
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause crash, execute
arbitrary code or expose sensitive information. (CVE-2025-1147)
It was discovered that GNU binutils incorrectly handled ce
Red Hat
hibernate-validator: Hibernate Validator Expression Language Injection
vendor_redhat·2025-06-03·CVSS 7.9
CVE-2025-35036 [HIGH] CWE-94 hibernate-validator: Hibernate Validator Expression Language Injection
hibernate-validator: Hibernate Validator Expression Language Injection
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
A flaw was found in Hibernate Validator. This vulnerability allows unauthorized acces
Red Hat
binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
vendor_redhat·2025-05-27·CVSS 4.8
CVE-2025-5245 [MEDIUM] CWE-119 binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
A denial-of-service vulnerability has been identified in GNU Binutils, affecting versions up to 2.44. The flaw resides within the debug_type_samep function in the /binutils/debug.c file of the objdump component. An attacker with local access can trigger a program crash by manipulating input data, leading to a denial of service for
Microsoft
GNU Binutils objdump debug.c debug_type_samep memory corruption
vendor_msrc·2025-05-13·CVSS 5.3
CVE-2025-5245 [MEDIUM] CWE-119 GNU Binutils objdump debug.c debug_type_samep memory corruption
GNU Binutils objdump debug.c debug_type_samep memory corruption
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https
Debian
CVE-2025-5245: binutils - A vulnerability classified as critical has been found in GNU Binutils up to 2.44...
vendor_debian·2025·CVSS 4.8
CVE-2025-5245 [MEDIUM] CVE-2025-5245: binutils - A vulnerability classified as critical has been found in GNU Binutils up to 2.44...
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.45-3)
sid: resolved (fixed in 2.45-3)
trixie: open
OSV
binutils vulnerabilities
osv·2025-12-01·CVSS 2.3
CVE-2025-11839 [LOW] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils could be forced to perform an out-
of-bounds read in certain instances. An attacker with local access to
a system could possibly use this issue to cause a denial of service.
(CVE-2025-11839, CVE-2025-11840)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2025-8225)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2025
OSV
binutils vulnerabilities
osv·2025-10-29·CVSS 4.8
CVE-2025-11082 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. The attack is restricted to local execution.
(CVE-2025-11082)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2025-11083, CVE-2025-5244, CVE-2025-5245,
CVE-2025-7554)
It was discovered that GNU binutils incorrectly handled certain files.
An attacker could possibly use this issue to cause crash, execute
arbitrary code or expose sensitive information. (CVE-2025-1147)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial
GHSA
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
ghsa·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] CWE-94 Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
GHSA
GHSA-h92g-mrpv-x8v2: A vulnerability classified as critical has been found in GNU Binutils up to 2
ghsa_unreviewed·2025-05-27
CVE-2025-5245 [MEDIUM] CWE-119 GHSA-h92g-mrpv-x8v2: A vulnerability classified as critical has been found in GNU Binutils up to 2
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
OSV
CVE-2025-5245: A vulnerability classified as critical has been found in GNU Binutils up to 2
osv·2025-05-27·CVSS 4.8
CVE-2025-5245 [MEDIUM] CVE-2025-5245: A vulnerability classified as critical has been found in GNU Binutils up to 2
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
bugzilla·2025-06-03·CVSS 8.8
CVE-2025-35036 [HIGH] CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
CVE-2025-35036 hibernate-validator: Hibernate Validator Expression Language Injection
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
Discussion:
This issue has been addressed in the following products:
Bugzilla
CVE-2025-5245 binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
bugzilla·2025-05-27·CVSS 7.8
CVE-2025-5245 [HIGH] CVE-2025-5245 binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
CVE-2025-5245 binutils: GNU Binutils objdump debug.c debug_type_samep memory corruption
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
https://sourceware.org/bugzilla/attachment.cgi?id=16004https://sourceware.org/bugzilla/show_bug.cgi?id=32829https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65ahttps://vuldb.com/?ctiid.310347https://vuldb.com/?id.310347https://vuldb.com/?submit.584635https://www.gnu.org/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
2025-05-27
Published