Logo
vulnerabilityCVE-2025-11412
Name
CVE-2025-11412
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
binutils
Patched

Vulnerability Ratings#


1.9
CVSSv4
3.3
CVSSv31
5.5
CVSSv31
1.7
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.43.1
Not Affected
buildroot
master
2.45.1
Not Affected
openwrt
master
2.46.0-r1
Not Affected
openwrt
openwrt-25.12
2.45.1-r1
Not Affected
yocto
kirkstone
2.38
Patched
yocto
master
2.46.1
Not Affected

Resolved with patches#


binutils (yocto:kirkstone)

#
Title
Author
Resolve
1
PR 33452 SEGV in bfd_elf_gc_record_vtentry
Alan Modra <amodra@gmail.com>
CVE-2025-11412

binutils (yocto:scarthgap)

#
Title
Author
Resolve
1
PR 33452 SEGV in bfd_elf_gc_record_vtentry
Alan Modra <amodra@gmail.com>
CVE-2025-11412