CVE-2025-5244

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*

History

03 Oct 2025, 14:46

Type Values Removed Values Added
First Time Gnu
Gnu binutils
CPE cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
References () https://sourceware.org/bugzilla/attachment.cgi?id=16010 - () https://sourceware.org/bugzilla/attachment.cgi?id=16010 - Broken Link
References () https://sourceware.org/bugzilla/show_bug.cgi?id=32858 - () https://sourceware.org/bugzilla/show_bug.cgi?id=32858 - Exploit, Issue Tracking
References () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5 - () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5 - Patch
References () https://vuldb.com/?ctiid.310346 - () https://vuldb.com/?ctiid.310346 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.310346 - () https://vuldb.com/?id.310346 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.584634 - () https://vuldb.com/?submit.584634 - Third Party Advisory, VDB Entry
References () https://www.gnu.org/ - () https://www.gnu.org/ - Product

28 May 2025, 15:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 13:15

Updated : 2025-10-03 14:46


NVD link : CVE-2025-5244

Mitre link : CVE-2025-5244

CVE.ORG link : CVE-2025-5244


JSON object : View

Products Affected

gnu

  • binutils
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer