Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5244

Опубликовано: 27 мая 2025
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.

A vulnerability was found in GNU Binutils 2.40 to version 2.44 and affects the elf_gc_sweep function of the bfd/elflink.c file of the component ld. The manipulation leads to memory corruption and a program crash. An attacker must have local access to exploit this vulnerability.

Отчет

The vulnerability relies upon the linker's -w command line option, which disables warnings and forces the linker to continue working even though it knows that it cannot produce valid output. With this option enabled a code path is exposed which leads to a dereferencing of a NULL pointer and the segmentation fault. The -w command line option was introduced with the 2.40 release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gcc-toolset-15-binutilsFix deferred
Red Hat Enterprise Linux 10gdbFix deferred
Red Hat Enterprise Linux 10mingw-binutilsFix deferred
Red Hat Enterprise Linux 6binutilsFix deferred
Red Hat Enterprise Linux 7binutilsNot affected
Red Hat Enterprise Linux 7gdbNot affected
Red Hat Enterprise Linux 8binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-13-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-13-gdbFix deferred
Red Hat Enterprise Linux 8gcc-toolset-14-binutilsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2368763binutils: GNU Binutils ld elflink.c elf_gc_sweep memory corruption

EPSS

Процентиль: 24%
0.00081
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.3
nvd
10 месяцев назад

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.3
msrc
9 месяцев назад

GNU Binutils ld elflink.c elf_gc_sweep memory corruption

CVSS3: 5.3
debian
10 месяцев назад

A vulnerability was found in GNU Binutils up to 2.44. It has been rate ...

rocky
2 месяца назад

Moderate: binutils security update

EPSS

Процентиль: 24%
0.00081
Низкий

4 Medium

CVSS3