CVE-2025-11495

⚪ Do wiadomości

Przepełnienie bufora w GNU Binutils umożliwia lokalne wykonanie kodu.

CVSS
3.3
EPSS
0.2%
Exploit
poc
Vendor
gnu
Opis źródłowy (NVD)

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.

buffer-overflow exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-08 20:15:34 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje