Junglewise Threat Intelligence

CVE-2025-11082: GNU Binutils heap overflow in _bfd_elf_parse_eh_frame

CVE-2025-11082 · Severity: medium · CVSS 5.3 · Published 2025-09-27

Technologies: Gnu Binutils. Vendors: Gnu.

Executive brief

GNU Binutils is a collection of binary tools used for creating and managing executable files and libraries. A security flaw in the linker component could allow a local attacker to cause a system crash or potentially execute unauthorized code by providing a specially crafted file. This could lead to a loss of system availability or unauthorized access to sensitive data on the affected machine.

Technical details

A heap-based buffer overflow vulnerability was identified in the `_bfd_elf_parse_eh_frame` function within `bfd/elf-eh-frame.c` of GNU Binutils 2.45. The flaw is rooted in the linker (ld) failing to properly validate section sizes, allowing a read/write beyond the allocated buffer when parsing `.eh_frame` sections. An attacker with local access can exploit this by passing a manipulated object file to the linker. This can result in a crash (AddressSanitizer: heap-buffer-overflow) or potentially arbitrary code execution. The issue is fixed in version 2.46 and via patch ea1a0737c7692737a644af0486b71e4a392cbca8.

Affected products

  • GNU Binutils 2.45

Timeline

  • 2025-09-19: other: Vulnerability reported to Sourceware Bugzilla
  • 2025-09-22: patched: Patch committed to master branch
  • 2025-09-27: disclosed: Initial advisory published

References

Related threats