A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.
References
Link | Resource |
---|---|
https://sourceware.org/bugzilla/attachment.cgi?id=16010 | Broken Link |
https://sourceware.org/bugzilla/show_bug.cgi?id=32858 | Exploit Issue Tracking |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5 | Patch |
https://vuldb.com/?ctiid.310346 | Permissions Required VDB Entry |
https://vuldb.com/?id.310346 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.584634 | Third Party Advisory VDB Entry |
https://www.gnu.org/ | Product |
Configurations
History
03 Oct 2025, 14:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://sourceware.org/bugzilla/attachment.cgi?id=16010 - Broken Link | |
References | () https://sourceware.org/bugzilla/show_bug.cgi?id=32858 - Exploit, Issue Tracking | |
References | () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5 - Patch | |
References | () https://vuldb.com/?ctiid.310346 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310346 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.584634 - Third Party Advisory, VDB Entry | |
References | () https://www.gnu.org/ - Product | |
CPE | cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* | |
First Time |
Gnu binutils
Gnu |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 May 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-27 13:15
Updated : 2025-10-03 14:46
NVD link : CVE-2025-5244
Mitre link : CVE-2025-5244
CVE.ORG link : CVE-2025-5244
JSON object : View
Products Affected
gnu
- binutils
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer