Logo
vulnerabilityCVE-2025-11840
Name
CVE-2025-11840
Source
NVD ( link)Debian ( link)
Description
A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
binutils
Patched

Vulnerability Ratings#


1.9
CVSSv4
3.3
CVSSv31
5.5
CVSSv31
1.7
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.43.1
Not Affected
buildroot
master
2.45.1
Not Affected
openwrt
master
2.46.0-r1
Not Affected
openwrt
openwrt-25.12
2.45.1-r1
Not Affected
yocto
master
2.46.1
Not Affected
yocto
scarthgap
2.42
Patched

Resolved with patches#


binutils (yocto:kirkstone)

#
Title
Author
Resolve
1
PR 33455 SEGV in vfinfo at ldmisc.c:527
Alan Modra <amodra@gmail.com>
CVE-2025-11840

binutils (yocto:scarthgap)

#
Title
Author
Resolve
1
PR 33455 SEGV in vfinfo at ldmisc.c:527
Alan Modra <amodra@gmail.com>
CVE-2025-11840