Logo
vulnerabilityCVE-2025-7546
Name
CVE-2025-7546
Source
NVD ( link)Debian ( link)
Description
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
binutils
Patched

Vulnerability Ratings#


1.9
CVSSv4
5.3
CVSSv31
7.8
CVSSv31
4.3
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.43.1
Not Affected
buildroot
master
2.45.1
Not Affected
openwrt
master
2.46.0-r1
Not Affected
openwrt
openwrt-25.12
2.45.1-r1
Not Affected
yocto
kirkstone
2.38
Patched
yocto
master
2.46.1
Not Affected

Resolved with patches#


binutils (yocto:kirkstone)

#
Title
Author
Resolve
1
elf: Report corrupted group section
"H.J. Lu" <hjl.tools@gmail.com>
CVE-2025-7546

binutils (yocto:scarthgap)

#
Title
Author
Resolve
1
elf: Report corrupted group section
"H.J. Lu" <hjl.tools@gmail.com>
CVE-2025-7546