PT-2025-4066 · Gnu+7 · Gnu Binutils+7

Wenjusun

·

Published

2025-01-29

·

Updated

2026-04-20

·

CVE-2025-0840

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils versions up to 2.43
Description A problematic issue was found in GNU Binutils, affecting the disassemble bytes function of the file binutils/objdump.c. The manipulation of the buf argument leads to a stack-based buffer overflow. It is possible to initiate the attack remotely, with a rather high complexity and difficult exploitability.
Recommendations GNU Binutils versions up to 2.43: Upgrade to version 2.44 to address this issue.

Exploit

Fix

DoS

Stack Overflow

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11299
ALT-PU-2025-11319
AZL-56099
AZL-56103
BDU:2025-03384
CVE-2025-0840
ECHO-F079-5D5A-AC2D
MGASA-2025-0084
OESA-2025-1098
OESA-2025-1099
OESA-2025-1100
OESA-2025-1128
OESA-2025-1129
OPENSUSE-SU-2025:15725-1
OPENSUSE-SU-2025:20150-1
SUSE-SU-2025:21195-1
SUSE-SU-2025:21197-1
SUSE-SU-2025:4096-1
SUSE-SU-2025_4096-1
USN-7306-1
USN-7423-2
USN-7899-1

Affected Products

Alt Linux
Astra Linux
Debian
Gnu Binutils
Linuxmint
Red Os
Suse
Ubuntu