CVE-2025-0840

EUVD-2025-1889
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
gnubinutils
𝑥
< 2.44
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
binutils
bookworm
unimportant
bullseye
unimportant
forky
2.46-3
fixed
sid
2.46-3
fixed
trixie
2.44-3
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
binutils
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
binutils-devel
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
binutils-devel-32bit
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libctf-nobfd0
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libctf0
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libucm-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucm0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucp-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucp0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucs-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucs0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libuct-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libuct0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
openucx-tools
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
perf
suse enterprise server 15 SP2
5.3.18-150200.25.11.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.38.7.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.44.20.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.52.5.1
fixed
perf-devel
suse enterprise server 15 SP4
5.14.21-150400.44.20.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.52.5.1
fixed