CVE-2025-1176

EUVD-2025-2050
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
gnubinutils
2.43
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
binutils
bookworm
unimportant
bullseye
unimportant
forky
2.46-3
fixed
sid
2.46-3
fixed
trixie
unimportant
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
binutils
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
binutils-devel
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
binutils-devel-32bit
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libctf-nobfd0
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libctf0
suse enterprise desktop 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise desktop 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise sap 15 SP7
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP2
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP3
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP4
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP5
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP6
2.45-150100.7.57.1
fixed
suse enterprise server 15 SP7
2.45-150100.7.57.1
fixed
libucm-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucm0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucp-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucp0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucs-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libucs0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libuct-devel
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
libuct0
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
openucx-tools
suse enterprise desktop 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise desktop 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise sap 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise sap 15 SP7
1.17.0-150700.4.2.7
fixed
suse enterprise server 15 SP2
1.6.0-150200.3.2.1
fixed
suse enterprise server 15 SP3
1.9.0-150300.4.2.5
fixed
suse enterprise server 15 SP4
1.11.1-150400.4.2.1
fixed
suse enterprise server 15 SP5
1.13.1-150500.4.2.5
fixed
suse enterprise server 15 SP6
1.15.0-150600.3.5.2
fixed
suse enterprise server 15 SP7
1.17.0-150700.4.2.7
fixed
perf
suse enterprise server 15 SP2
5.3.18-150200.25.11.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.38.7.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.44.20.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.52.5.1
fixed
perf-devel
suse enterprise server 15 SP4
5.14.21-150400.44.20.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.52.5.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
binutils
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
binutils-debuginfo
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
binutils-debugsource
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
binutils-devel
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
binutils-gprofng
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
binutils-gprofng-debuginfo
Amazon Linux 2023
0:2.41-50.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
binutils
Azure Linux 3.0
0:2.41-3.azl3
fixed
CBL-Mariner 2.0
0:2.37-12.cm2
fixed
gdb
Azure Linux 3.0
0:13.2-9.azl3
fixed
CBL-Mariner 2.0
0:11.2-4.cm2
fixed