PT-2025-6044 · Gnu+4 · Gnu Binutils+4
Wenjusun
·
Published
2025-01-14
·
Updated
2026-04-20
·
CVE-2025-1147
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.43
Description
A problem has been found in the function
sanitizer::internal strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.Recommendations
For GNU Binutils version 2.43, as a temporary workaround, consider restricting access to the function
sanitizer::internal strlen until a patch is available. Additionally, be cautious when using the const argument to minimize the risk of buffer overflow exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Gnu Binutils
Linuxmint
Suse
Ubuntu