Junglewise Threat Intelligence

CVE-2025-11840: GNU Binutils out-of-bounds read in vfinfo function

CVE-2025-11840 · Severity: low · CVSS 3.3 · Published 2025-10-16

Technologies: Gnu Binutils. Vendors: Gnu.

Executive brief

GNU Binutils is a collection of binary tools used by developers to create and manage executable files. A vulnerability in the linker component (ld) could allow a local user to cause a system crash or service disruption by processing a specially crafted file. While the impact is primarily limited to a denial-of-service, it could affect automated software build pipelines or development environments.

Technical details

An out-of-bounds read vulnerability exists in GNU Binutils 2.45 within the vfinfo function of ldmisc.c. The issue is triggered when the linker (ld) processes a relocation table containing an illegal symbol index or a relocation 'howto' structure with a NULL name, leading to a NULL pointer dereference and subsequent segmentation fault (SEGV). An attacker with local access can exploit this by providing a manipulated object file to the linker. The vulnerability was addressed in the master branch (commit f6b0f53) by ensuring the relocation table slurp process does not allow howto structures with NULL names, with a formal fix targeted for version 2.46.

Affected products

  • GNU Binutils 2.45

Timeline

  • 2025-09-18: disclosed: Bug reported to GNU Sourceware Bugzilla by Yifan Zhang
  • 2025-09-18: other: Initial patch proposed by H.J. Lu
  • 2025-10-16: advisory: CVE-2025-11840 published
  • 2025-11-03: patched: Fix committed to master branch for version 2.46

References

Related threats