F5-K000159667: Buffer Overflow
CVE-2025-11082 A flaw has been found in GNU Binutils 2.45. Impacted is the function bfdelfparseehframe of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46". CVE-2025-11083 A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elfswapshdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000159667?
F5-K000159667 has been assessed as a high severity vulnerability due to the potential for heap-based buffer overflow.
How do I fix F5-K000159667?
To fix F5-K000159667, upgrade to the appropriate patched version of F5OS-A or F5OS-C as specified in the advisory.
What products are affected by F5-K000159667?
F5-K000159667 affects specific versions of F5OS-A and F5OS-C, including versions ranging from 1.5.1 to 1.8.3.
Is remote execution possible with F5-K000159667?
No, the exploitation of F5-K000159667 is restricted to local execution only.
What component is impacted by F5-K000159667?
F5-K000159667 impacts the Linker component, specifically the function _bfd_elf_parse_eh_frame in GNU Binutils.