USN-7423-1: GNU binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash, expose sensitive information or execute arbitrary code. (CVE-2025-1153, CVE-2025-1182) It was discovered that ld in GNU binutils incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-1176) It was discovered that ld in GNU binutils incorrectly handled certain files. An attacker could possibly use this issue to cause a crash, expose sensitive information or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. (CVE-2025-1178, CVE-2025-1181)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7423-1?
USN-7423-1 is considered a serious vulnerability that can lead to a crash, exposure of sensitive information, or arbitrary code execution.
How do I fix USN-7423-1?
To remediate USN-7423-1, update to the latest version of the binutils package as specified in the advisory.
What systems are affected by USN-7423-1?
USN-7423-1 affects Ubuntu versions 20.04, 22.04, and 24.10, specifically certain versions of the binutils and binutils-multiarch packages.
What types of attacks can exploit USN-7423-1?
An attacker can exploit USN-7423-1 to cause application crashes, access sensitive data, or execute malicious code on the affected systems.
Is there a known exploit for USN-7423-1?
As of now, there are no publicly disclosed exploits targeting USN-7423-1, but the vulnerability's potential severity highlights the need for prompt updates.