CVE-2025-11083Patch(gnu / binutils)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu binutils systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • binutils

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
binutils

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-04: 1Mentions · 2026-05-11: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 103-0405-11
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-041
Patch1
2026-05-111
General1
Full discourse2 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Juniper ❗ CVE-2025-38248 ❗ CVE-2025-38129 ❗ CVE-2025-11083 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-juniper-2/ https://t.co/2UaEIJBKAy

    Post summary

    The post lists several Juniper product CVEs and links to more information, but provides no PoC, exploit, active exploitation, patches, or technical details.

    010101.1K
    6.7K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 release avr-binutils updates fixing heap overflow flaws CVE-2025-11081, CVE-2025-11082, CVE-2025-11083 that risk out-of-bounds reads and memory corruption. Update now. https://threatcluster.io/cluster/fedora-42-and-43-address-severe-heap-overflow-vulnerabilitie-83fdeedc

    Post summary

    Fedora 42 and 43 have released avr‑binutils updates that fix three heap overflow CVEs (CVE‑2025‑11081, CVE‑2025‑11082, CVE‑2025‑11083), addressing out‑of‑bounds reads and memory corruption; users are urged to apply the update.

    0000069
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnubinutils2.45--

Explore more