CVE-2025-5244: GNU Binutils ld elflink.c elf_gc_sweep memory corruption
A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elfgcsweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.
Other sources
GNU Binutils ld elflink.c elfgcsweep memory corruption
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.37-15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2-9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.2-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-6 - Upgrade
Upgrade
gnu/binutils/ldto a version that resolves this vulnerability.Fixed in 2.45
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5244?
CVE-2025-5244 is rated as critical due to the memory corruption vulnerability in GNU Binutils.
What software is affected by CVE-2025-5244?
CVE-2025-5244 affects GNU Binutils versions up to and including 2.44.
How do I fix CVE-2025-5244?
To fix CVE-2025-5244, upgrade GNU Binutils to version 2.45 or later.
What kind of attack does CVE-2025-5244 allow?
CVE-2025-5244 allows local attackers to manipulate memory, leading to potential exploitation.
Where is the vulnerability located in CVE-2025-5244?
CVE-2025-5244 is found in the function elf_gc_sweep within the bfd/elflink.c file of GNU Binutils.