PT-2025-23003 · Gnu+7 · Gnu Binutils+7

Lcyf-Fizz

·

Published

2025-03-31

·

Updated

2026-04-20

·

CVE-2025-5245

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions up to 2.44
Description A critical vulnerability has been found in GNU Binutils, affecting the debug type samep function of the objdump component. This issue leads to memory corruption and requires local access to exploit. The exploit has been publicly disclosed.
Recommendations For GNU Binutils versions up to 2.44, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the objdump component until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12767
AZL-61983
AZL-61988
BDU:2025-10924
BDU:2025-10925
CVE-2025-5245
ECHO-CE84-FABC-3AE3
OPENSUSE-SU-2025:15651-1
OPENSUSE-SU-2025:20150-1
SUSE-SU-2025:21195-1
SUSE-SU-2025:21197-1
SUSE-SU-2025:4096-1
USN-7847-1
USN-7899-1

Affected Products

Alt Linux
Astra Linux
Debian
Gnu Binutils
Linuxmint
Red Os
Suse
Ubuntu