Out-of-Bounds Read Vulnerability in GNU Binutils Linker
CVE-2025-11413
Key Information:
Badges
What is CVE-2025-11413?
A vulnerability exists in the GNU Binutils 2.45 version, specifically in the elf_link_add_object_symbols function of elflink.c within the Linker component. This flaw allows for out-of-bounds read access, posing a potential security risk. Successful exploitation can happen locally, making it crucial for users to upgrade to version 2.46, which includes a patch identified by the commit hash 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Failure to address this vulnerability may enable attackers to exploit the flaw, impacting the system's integrity.
Affected Version(s)
Binutils 2.45
Binutils 2.46
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved