PT-2025-22998 · Gnu+7 · Gnu Binutils+7

Lcyf-Fizz

·

Published

2025-04-09

·

Updated

2026-04-20

·

CVE-2025-5244

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions up to 2.44
Description A critical issue was found in GNU Binutils, affecting the elf gc sweep function of the ld component. This issue leads to memory corruption and can be exploited locally. The exploit has been disclosed publicly and may be used.
Recommendations For GNU Binutils versions up to 2.44, upgrade to version 2.45 to address this issue. As a temporary workaround, consider disabling the elf gc sweep function until a patch is available. Restrict access to the bfd/elflink.c file to minimize the risk of exploitation. Avoid using the affected ld component until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:20155
ALT-PU-2025-12767
AZL-61982
AZL-61994
AZL-62047
BDU:2025-10924
CVE-2025-5244
ECHO-F8C4-E042-8153
OPENSUSE-SU-2025:15651-1
OPENSUSE-SU-2025:20150-1
RHSA-2025:20155
SUSE-SU-2025:21195-1
SUSE-SU-2025:21197-1
SUSE-SU-2025:4096-1
USN-7847-1
USN-7899-1

Affected Products

Alt Linux
Astra Linux
Debian
Gnu Binutils
Linuxmint
Red Os
Suse
Ubuntu