VDB
DEBIAN-CVE-2025-11082
DEBIAN-CVE-2025-11082
PUBLISHED
CVSS 7.800000190734863 HIGH
A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | binutils | 0, 2.44-3, 2.44.50.20250201-1 |
| Debian:14 | binutils | 2.44-3, 2.44.50.20250201-1, 2.44.50.20250207-1 |
| Debian:12 | binutils | 0, 2.40-2, 2.40.50.20230501-1 |
| Debian:11 | binutils | 0, 2.35.2-2, 2.35.50.20201125-1 |
Timeline
- Sep 27, 2025 CVE Published
- Apr 28, 2026 CVE Updated