We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3198

GNU Binutils objdump bucomm.c display_info memory leak



Description

EN DE

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

In GNU Binutils 2.43/2.44 wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Das betrifft die Funktion display_info der Datei binutils/bucomm.c der Komponente objdump. Mit der Manipulation mit unbekannten Daten kann eine memory leak-Schwachstelle ausgenutzt werden. Der Angriff muss lokal angegangen werden. Der Exploit steht zur öffentlichen Verfügung. Der Patch wird als ba6ad3a18cb26b79e0e3b84c39f707535bbc344d bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.

Reserved 2025-04-03 | Published 2025-04-04 | Updated 2025-04-04 | Assigner VulDB


MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
LOW: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
LOW: 3.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
1.7AV:L/AC:L/Au:S/C:N/I:N/A:P

Problem types

Memory Leak

Denial of Service

Product status

2.43
affected

2.44
affected

Timeline

2025-04-03:Advisory disclosed
2025-04-03:VulDB entry created
2025-04-03:VulDB entry last update

Credits

Haoxin Tu (VulDB User) reporter

References

vuldb.com/?id.303151 (VDB-303151 | GNU Binutils objdump bucomm.c display_info memory leak) vdb-entry technical-description

vuldb.com/?ctiid.303151 (VDB-303151 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.545773 (Submit #545773 | GNU Library Objdump in Binutil 2.44 and 2.43 (also other possible downward versions) Memory Leak) third-party-advisory

sourceware.org/bugzilla/show_bug.cgi?id=32716 issue-tracking

sourceware.org/bugzilla/show_bug.cgi?id=32716 exploit issue-tracking

sourceware.org/...h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d patch

www.gnu.org/ product

cve.org (CVE-2025-3198)

nvd.nist.gov (CVE-2025-3198)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3198

Support options

Helpdesk Chat, Email, Knowledgebase