VDB

DEBIAN-CVE-2025-11082

DEBIAN-CVE-2025-11082 PUBLISHED CVSS 7.800000190734863 HIGH

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13binutils0, 2.44-3, 2.44.50.20250201-1
Debian:14binutils2.44-3, 2.44.50.20250201-1, 2.44.50.20250207-1
Debian:12binutils0, 2.40-2, 2.40.50.20230501-1
Debian:11binutils0, 2.35.2-2, 2.35.50.20201125-1

Timeline

  • Sep 27, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›