CVE-2025-8224
published 2025-07-27CVE-2025-8224: A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.43.1-4 (forky) | binutils 2.43.1-4 (forky) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.43.1-4 | 2.43.1-4 |
| gnu | binutils | >= 0 < 2.43.1-4 | 2.43.1-4 |
| msrc | azl3_binutils_2.41-7_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_binutils_2.37-16_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_msrc5.5MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-8224: A vulnerability has been found in GNU Binutils 2
osv·2025-07-27·CVSS 4.8
CVE-2025-8224 [MEDIUM] CVE-2025-8224: A vulnerability has been found in GNU Binutils 2
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
GHSA
GHSA-jff4-5h8q-wpxm: A vulnerability has been found in GNU Binutils 2
ghsa_unreviewed·2025-07-27
CVE-2025-8224 [MEDIUM] CWE-404 GHSA-jff4-5h8q-wpxm: A vulnerability has been found in GNU Binutils 2
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
Red Hat
binutils: Binutils BFD Null Pointer Dereference
vendor_redhat·2025-07-27·CVSS 4.8
CVE-2025-8224 [MEDIUM] CWE-476 binutils: Binutils BFD Null Pointer Dereference
binutils: Binutils BFD Null Pointer Dereference
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
A flaw was found in binutils. The `bfd_elf_get_str_section` function in the BFD Library’s `bfd/elf.c` file exhibits a null pointer dereference due to manipulation, potentially allowing a local attacker to trigger a denial of service. This occurs when processing spec
Microsoft
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
vendor_msrc·2025-07-08·CVSS 5.5
CVE-2025-8224 [MEDIUM] CWE-476 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Debian
CVE-2025-8224: binutils - A vulnerability has been found in GNU Binutils 2.44 and classified as problemati...
vendor_debian·2025·CVSS 4.8
CVE-2025-8224 [MEDIUM] CVE-2025-8224: binutils - A vulnerability has been found in GNU Binutils 2.44 and classified as problemati...
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.43.1-4)
sid: resolved (fixed in 2.43.1-4)
trixie: resolved (fixed in 2.43.1-4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sourceware.org/bugzilla/attachment.cgi?id=15680https://sourceware.org/bugzilla/show_bug.cgi?id=32109https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530https://vuldb.com/?ctiid.317812https://vuldb.com/?id.317812https://vuldb.com/?submit.621878https://www.gnu.org/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
2025-07-27
Published