CVE-2025-11414: GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds
A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function getlinkhashentry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.
Other sources
GNU Binutils Linker elflink.c getlinkhashentry out-of-bounds
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutils Linker elflink.c (get_link_hash_entry)to a version that resolves this vulnerability.Fixed in 2.46Patch aeaaa9af6359c8e394ce9cf24911fec4f4d23703
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11414?
CVE-2025-11414 is classified as a medium severity vulnerability affecting GNU Binutils.
How do I fix CVE-2025-11414?
To fix CVE-2025-11414, it is recommended to update to a patched version of GNU Binutils.
What kind of attack can be executed with CVE-2025-11414?
CVE-2025-11414 allows for a local attack that can lead to an out-of-bounds read.
Which versions of GNU Binutils are affected by CVE-2025-11414?
CVE-2025-11414 affects GNU Binutils version 2.45.
Can CVE-2025-11414 be exploited remotely?
No, CVE-2025-11414 can only be exploited locally.