We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-5245

GNU Binutils objdump debug.c debug_type_samep memory corruption



Description

EN DE

A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Es wurde eine Schwachstelle in GNU Binutils bis 2.44 entdeckt. Sie wurde als kritisch eingestuft. Es geht dabei um die Funktion debug_type_samep der Datei /binutils/debug.c der Komponente objdump. Durch Manipulation mit unbekannten Daten kann eine memory corruption-Schwachstelle ausgenutzt werden. Der Angriff muss lokal erfolgen. Der Exploit steht zur öffentlichen Verfügung. Als bestmögliche Massnahme wird Patching empfohlen.

Reserved 2025-05-27 | Published 2025-05-27 | Updated 2025-05-27 | Assigner VulDB


MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
MEDIUM: 5.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
MEDIUM: 5.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
4.3AV:L/AC:L/Au:S/C:P/I:P/A:P

Problem types

Memory Corruption

Product status

2.0
affected

2.1
affected

2.2
affected

2.3
affected

2.4
affected

2.5
affected

2.6
affected

2.7
affected

2.8
affected

2.9
affected

2.10
affected

2.11
affected

2.12
affected

2.13
affected

2.14
affected

2.15
affected

2.16
affected

2.17
affected

2.18
affected

2.19
affected

2.20
affected

2.21
affected

2.22
affected

2.23
affected

2.24
affected

2.25
affected

2.26
affected

2.27
affected

2.28
affected

2.29
affected

2.30
affected

2.31
affected

2.32
affected

2.33
affected

2.34
affected

2.35
affected

2.36
affected

2.37
affected

2.38
affected

2.39
affected

2.40
affected

2.41
affected

2.42
affected

2.43
affected

2.44
affected

Timeline

2025-05-27:Advisory disclosed
2025-05-27:VulDB entry created
2025-05-27:VulDB entry last update

Credits

lcyf-fizz (VulDB User) reporter

References

vuldb.com/?id.310347 (VDB-310347 | GNU Binutils objdump debug.c debug_type_samep memory corruption) vdb-entry technical-description

vuldb.com/?ctiid.310347 (VDB-310347 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.584635 (Submit #584635 | GNU Binutils objdump 2.44 Memory Corruption) third-party-advisory

sourceware.org/bugzilla/show_bug.cgi?id=32829 issue-tracking

sourceware.org/bugzilla/attachment.cgi?id=16004 exploit

sourceware.org/...h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a patch

www.gnu.org/ broken-link product

cve.org (CVE-2025-5245)

nvd.nist.gov (CVE-2025-5245)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-5245

Support options

Helpdesk Chat, Email, Knowledgebase