CVE-2025-11082

Source
https://cve.org/CVERecord?id=CVE-2025-11082
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11082.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-11082
Downstream
AZL (6)
BELL (1)
CGA (8)
CLEANSTART (3)
CLSA (12)
DEBIAN (1)
ECHO (1)
MINI (1)
OESA (6)
RHSA (4)
RLSA (1)
ROOT (1)
UBUNTU (1)
Related
Published
2025-09-27T22:32:09Z
Modified
2026-08-27T03:30:22Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow
Details

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11082.json"
}
References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnu:binutils:2.45:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.45"
        },
        {
            "last_affected":  "2.45"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

2.*
2.45
Other
binutils-2_45

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11082.json"