USN-7423-2: GNU binutils vulnerabilities
USN-7423-1 fixed several vulnerabilities in GNU. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2025-0840) It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash, expose sensitive information or execute arbitrary code. (CVE-2025-1153) It was discovered that ld in GNU binutils incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-1176)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7423-2?
The severity of USN-7423-2 is considered critical due to potential exploitation by an attacker.
How do I fix USN-7423-2?
To fix USN-7423-2, update your binutils and binutils-multiarch packages to the recommended versions for your Ubuntu release.
Which Ubuntu versions are affected by USN-7423-2?
USN-7423-2 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS users.
What vulnerabilities are addressed in USN-7423-2?
USN-7423-2 addresses multiple vulnerabilities in GNU binutils that may lead to denial of service or other impacts.
Is there a risk of exploitation from USN-7423-2 vulnerabilities?
Yes, there is a risk of exploitation if the affected systems are not updated promptly.