Gnu · Gnu Binutils · CVE-2025-1149
**Name of the Vulnerable Software and Affected Versions**
GNU Binutils version 2.43
**Description**
A memory leak vulnerability has been found in the ld component of GNU Binutils, specifically affecting the `xstrdup` function in the `libiberty/xmalloc.c` file. This issue can be exploited remotely, with a relatively high complexity of attack. The exploitability is considered difficult. The vulnerability allows for a memory leak, which can be initiated remotely.
**Recommendations**
To fix this issue, it is recommended to apply a patch. The code maintainer has fixed all reported leaks in the binutils master branch, but has not committed these fixes to the 2.44 branch due to concerns about destabilizing ld. As a temporary workaround, consider restricting the use of the `xstrdup` function in the affected ld component until a patch is available.