Home

Description

EN DE

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. This patch is called 16357. It is best practice to apply a patch to resolve this issue.

In GNU Binutils 2.45 ist eine Schwachstelle entdeckt worden. Davon betroffen ist die Funktion vfinfo der Datei ldmisc.c. Die Bearbeitung verursacht out-of-bounds read. Der Angriff muss lokal durchgeführt werden. Der Exploit steht zur öffentlichen Verfügung. Der Name des Patches ist 16357. Als bestmögliche Massnahme wird Patching empfohlen.

PUBLISHED Reserved 2025-10-16 | Published 2025-10-16 | Updated 2025-10-16 | Assigner VulDB




MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
LOW: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
LOW: 3.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
1.7AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C

Problem types

Out-of-Bounds Read

Memory Corruption

Product status

2.45
affected

Timeline

2025-10-16:Advisory disclosed
2025-10-16:VulDB entry created
2025-10-16:VulDB entry last update

Credits

JJLeo (VulDB User) reporter

References

vuldb.com/?id.328775 (VDB-328775 | GNU Binutils ldmisc.c vfinfo out-of-bounds) vdb-entry technical-description

vuldb.com/?ctiid.328775 (VDB-328775 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.661281 (Submit #661281 | GNU Binutils 2.45 Out-of-Bounds Read) third-party-advisory

sourceware.org/bugzilla/show_bug.cgi?id=33455 issue-tracking

sourceware.org/bugzilla/attachment.cgi?id=16351 exploit

sourceware.org/bugzilla/attachment.cgi?id=16357 patch

www.gnu.org/ product

cve.org (CVE-2025-11840)

nvd.nist.gov (CVE-2025-11840)

Download JSON