Executive brief
A vulnerability exists in the GNU Binutils linker, a tool used by developers to combine compiled code into executable programs. An attacker with local access to a system could use a specially crafted file to cause the linker to crash or behave unexpectedly. This could disrupt software development processes or be used as part of a more complex attack chain, though it primarily impacts the availability of the tool during the linking process.
Technical details
A heap-based buffer overflow exists in the GNU Binutils linker (ld) within the elf_x86_64_relocate_section function in bfd/elf64-x86-64.c. The issue stems from improper handling of Thread Local Storage (TLS) relocations when they are applied to non-executable or non-progbits sections. A local attacker can exploit this by providing a malformed object file to the linker, causing an out-of-bounds read/write (SEGV). The vulnerability was addressed by disallowing TLS relocations in non-SHT_PROGBITS and non-SHF_EXECINSTR sections. A patch has been committed to the master branch (6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0).
Affected products
- GNU Binutils 2.45, 2.46
Timeline
- 2025-09-28: disclosed: Bug reported to Sourceware Bugzilla by Yifan Zhang
- 2025-10-02: patched: Fix committed to binutils-gdb master branch
- 2025-10-08: advisory: CVE-2025-11495 published
References
- https://sourceware.org/bugzilla/attachment.cgi?id=16393
- https://sourceware.org/bugzilla/show_bug.cgi?id=33502
- https://sourceware.org/bugzilla/show_bug.cgi?id=33502
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0
- https://vuldb.com/?ctiid.327620
- https://vuldb.com/?id.327620
- https://vuldb.com/?submit.668290