๐Ÿ” CVE Alert

CVE-2025-11414

LOW 3.3

GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.

CWE CWE-125 CWE-119
Vendor gnu
Product binutils
Published Oct 7, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for gnu binutils

Be the first to know when new low vulnerabilities affecting gnu binutils are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GNU / Binutils
2.45

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.327350 vuldb.com: https://vuldb.com/?ctiid.327350 vuldb.com: https://vuldb.com/?submit.665591 sourceware.org: https://sourceware.org/bugzilla/show_bug.cgi?id=33450 sourceware.org: https://sourceware.org/bugzilla/attachment.cgi?id=16361 sourceware.org: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703 gnu.org: https://www.gnu.org/

Credits

๐Ÿ” Yifan Zhang (VulDB User)