Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-11495

Опубликовано: 08 окт. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.7
CVSS3: 3.3

Описание

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.

РелизСтатусПримечание
devel

not-affected

2.45.50.20251125-1ubuntu1
esm-infra-legacy/trusty

ignored

changes too intrsuive
esm-infra/bionic

ignored

changes too intrsuive
esm-infra/focal

ignored

changes too intrsuive
esm-infra/xenial

ignored

changes too intrsuive
jammy

ignored

changes too intrsuive
noble

ignored

changes too intrusive
plucky

released

2.44-3ubuntu1.3
questing

released

2.45-7ubuntu1.2
upstream

released

2.46

Показывать по

EPSS

Процентиль: 7%
0.00027
Низкий

1.7 Low

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
4 месяца назад

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.

msrc
4 месяца назад

GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow

CVSS3: 3.3
debian
4 месяца назад

A vulnerability was determined in GNU Binutils 2.45. The affected elem ...

CVSS3: 3.3
github
4 месяца назад

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
fstec
4 месяца назад

Уязвимость функции elf_x86_64_relocate_section компонента elf64-x86-64.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 7%
0.00027
Низкий

1.7 Low

CVSS2

3.3 Low

CVSS3