Logo
vulnerabilityCVE-2025-0840
Name
CVE-2025-0840
Source
NVD ( link)Debian ( link)
Description
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
binutils
Patched

Vulnerability Ratings#


6.3
CVSSv4
5
CVSSv31
7.5
CVSSv31
5.1
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.43.1
Exploitable
buildroot
master
2.45.1
Not Affected
openwrt
master
2.46.0-r1
Not Affected
openwrt
openwrt-25.12
2.45.1-r1
Not Affected
yocto
master
2.46.1
Not Affected
yocto
scarthgap
2.42
Patched

Resolved with patches#


binutils (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com>
CVE-2025-0840

binutils (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Deepesh Varatharajan <Deepesh.Varatharajan@windriver.com>
CVE-2025-0840