CVE-2025-11494

⚪ Do wiadomości

Błąd odczytu poza granicami w GNU Binutils umożliwia lokalne ataki.

CVSS
3.3
EPSS
0.2%
Exploit
poc
Vendor
gnu
Opis źródłowy (NVD)

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-08 20:15:34 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje