CVE-2025-11083: GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow
A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elfswapshdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".
Other sources
GNU Binutils Linker elfcode.h elfswapshdr heap-based overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.37-19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.2-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.0-3 - Upgrade
Upgrade
GNU Binutilsto a version that resolves this vulnerability.Fixed in 2.46Patch 9ca499644a21ceb3f946d1c179c38a83be084490 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ea1a0737c7692737a644af0486b71e4a392cbca8
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11083?
CVE-2025-11083 has a high severity due to the potential for heap-based buffer overflow exploits.
How do I fix CVE-2025-11083?
To fix CVE-2025-11083, update to the patched version of GNU Binutils that resolves the buffer overflow issue.
What versions of GNU Binutils are affected by CVE-2025-11083?
CVE-2025-11083 affects GNU Binutils version 2.45.
Can CVE-2025-11083 be exploited remotely?
No, CVE-2025-11083 requires local access to exploit the vulnerability.
What components are involved in CVE-2025-11083?
CVE-2025-11083 specifically involves the Linker component, particularly the elf_swap_shdr function in the bfd/elfcode.h library.