CVE-2025-1176: GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function bfdelfgcmarkrsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.
Other sources
GNU Binutils ld elflink.c bfdelfgcmarkrsec heap-based overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.2-9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.37-12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2-4 - Upgrade
Upgrade
GNU Binutils (ld, elflink.c:_bfd_elf_gc_mark_rsec)to a version that resolves this vulnerability.Fixed in 2.43Patch f9978defb6fab0bd8583942d97c112b0932ac814
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1176?
CVE-2025-1176 is classified as a critical severity vulnerability.
What type of vulnerability is CVE-2025-1176?
CVE-2025-1176 is a heap-based buffer overflow vulnerability.
How can CVE-2025-1176 be exploited?
CVE-2025-1176 can be exploited remotely by an attacker.
Which component of GNU Binutils is affected by CVE-2025-1176?
CVE-2025-1176 affects the ld component within GNU Binutils.
How do I fix CVE-2025-1176?
To fix CVE-2025-1176, you should update GNU Binutils to the latest stable version that includes the necessary patches.