Memory Leak Vulnerability in GNU Binutils by GNU
CVE-2025-1152
2.3LOW
What is CVE-2025-1152?
A memory leak has been discovered in the xstrdup function within the GNU Binutils component ld, specifically in version 2.43. This vulnerability can be exploited remotely, although the complexity of execution is considered high, making the attack challenging. Users are advised to apply patches to mitigate this issue, as the exploit has been disclosed publicly. The code maintainer noted reluctance in committing specific leak fixes to avoid destabilizing the ld component, but all known memory leak issues have been addressed in the binutils master branch.
Affected Version(s)
Binutils 2.43