CVE-2025-11082Patch(gnu / binutils)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu binutils systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • binutils

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
binutils

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-04: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 103-04
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 release avr-binutils updates fixing heap overflow flaws CVE-2025-11081, CVE-2025-11082, CVE-2025-11083 that risk out-of-bounds reads and memory corruption. Update now. https://threatcluster.io/cluster/fedora-42-and-43-address-severe-heap-overflow-vulnerabilitie-83fdeedc

    Post summary

    Fedora 42 and 43 have released avr-binutils updates that fix three heap overflow CVEs (CVE-2025-11081, CVE-2025-11082, CVE-2025-11083), addressing out-of-bounds reads and memory corruption; users are urged to apply the update.

    0000069
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnubinutils2.45--

Explore more