Junglewise Threat Intelligence

CVE-2025-11083: GNU Binutils heap overflow in elf_swap_shdr

CVE-2025-11083 · Severity: medium · CVSS 5.3 · Published 2025-09-27

Technologies: Gnu Binutils. Vendors: Gnu.

Executive brief

A vulnerability exists in GNU Binutils, a collection of programming tools used for creating and managing executable files and libraries. An attacker with local access could use a specially crafted file to cause a system crash or potentially execute unauthorized code. This could disrupt development operations or allow an attacker to gain further control over a local system.

Technical details

A heap-based buffer overflow vulnerability exists in GNU Binutils 2.45 within the BFD library's ELF processing logic. Specifically, the 'elf_swap_shdr' function in 'bfd/elfcode.h' fails to properly validate section headers in linker input files. A local attacker can provide a malformed ELF object that triggers a buffer overflow during memory allocation or section content copying (e.g., in 'cache_bwrite' or 'bfd_get_full_section_contents'). This can result in a denial of service (linker crash) or potentially arbitrary code execution. The issue is addressed in version 2.46 by ensuring 'elf_swap_shdr_in' returns false for corrupt headers, causing the linker to reject the invalid input.

Affected products

  • GNU Binutils 2.45

Timeline

  • 2025-09-18: disclosed: Bug reported to Sourceware Bugzilla
  • 2025-09-23: patched: Patch committed to master branch
  • 2025-09-27: advisory: NVD publication date

References

Related threats