CVE-2025-11495: GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow
A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elfx8664relocatesection of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.
Other sources
GNU Binutils Linker elf64-x86-64.c elfx8664relocatesection heap-based overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutilsto a version that resolves this vulnerability.Patch 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11495?
CVE-2025-11495 has a high severity due to its potential to cause a heap-based buffer overflow.
How do I fix CVE-2025-11495?
To fix CVE-2025-11495, upgrade to a patched version of GNU Binutils that addresses the vulnerability.
What components of GNU Binutils are affected by CVE-2025-11495?
CVE-2025-11495 affects the linker component, specifically the elf_x86_64_relocate_section function in elf64-x86-64.c.
Can CVE-2025-11495 be exploited remotely?
CVE-2025-11495 can only be exploited locally, requiring user-level access to the affected system.
What type of vulnerability is CVE-2025-11495?
CVE-2025-11495 is classified as a heap-based buffer overflow vulnerability.