CVE-2025-5245: GNU Binutils objdump debug.c debug_type_samep memory corruption
A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debugtypesamep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Other sources
GNU Binutils objdump debug.c debugtypesamep memory corruption
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.37-15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5245?
CVE-2025-5245 is classified as a critical vulnerability.
What components are affected by CVE-2025-5245?
CVE-2025-5245 affects GNU Binutils versions up to 2.44, specifically the objdump component.
How does CVE-2025-5245 operate?
CVE-2025-5245 leads to memory corruption through manipulation in the function debug_type_samep.
What is required to exploit CVE-2025-5245?
Exploitation of CVE-2025-5245 requires local access to the affected system.
How do I fix CVE-2025-5245?
To fix CVE-2025-5245, you should update GNU Binutils to a version later than 2.44.