CVE-2025-1180: GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function bfdelfwritesectionehframe of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Other sources
GNU Binutils ld elf-eh-frame.c bfdelfwritesectionehframe memory corruption
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.4-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.1-5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1180?
CVE-2025-1180 is classified as a problematic vulnerability due to its potential for remote memory corruption.
How do I fix CVE-2025-1180?
To fix CVE-2025-1180, update GNU Binutils to a patched version that addresses the memory corruption issue.
What software is affected by CVE-2025-1180?
CVE-2025-1180 affects GNU Binutils version 2.43.
Can CVE-2025-1180 be exploited remotely?
Yes, CVE-2025-1180 can be exploited remotely, enabling attackers to manipulate memory.
What component of GNU Binutils is impacted by CVE-2025-1180?
CVE-2025-1180 impacts the function _bfd_elf_write_section_eh_frame in the ld component of GNU Binutils.