PT-2025-6053 · Gnu+5 · Gnu Binutils+5

Wenjusun

·

Published

2025-02-05

·

Updated

2025-12-12

·

CVE-2025-1181

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.43
Description A critical vulnerability was found in GNU Binutils, affecting the function bfd elf gc mark rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high, and the exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply a patch with the name 931494c9a89558acb36a03a340c01726545eef24. As a temporary workaround, consider disabling the bfd elf gc mark rsec function until a patch is available. Restrict access to the vulnerable component ld to minimize the risk of exploitation. Avoid using the affected bfd/elflink.c file until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-56558
AZL-56664
BDU:2025-11824
CVE-2025-1181
ECHO-2D82-28F6-B8F6
MGASA-2025-0262
OPENSUSE-SU-2025:15651-1
OPENSUSE-SU-2025:20150-1
SUSE-SU-2025:21195-1
SUSE-SU-2025:21197-1
SUSE-SU-2025:4096-1
USN-7423-1
USN-7899-1

Affected Products

Astra Linux
Debian
Gnu Binutils
Linuxmint
Suse
Ubuntu