CVE-2025-1148
CVSS 3.1 Score 3.1 of 10 (low)
Details
Summary
CVE-2025-1148 is a newly discovered vulnerability affecting the GNU Binutils 2.43 version. The issue lies within the link_order_scan function of the ldelfgen.c component in the ld part of Binutils. This weakness results in a memory leak, which can be exploited remotely. The complexity of an attack is considered high, and the exploitation is reportedly challenging. The code maintainer has acknowledged the issue but has not yet incorporated the fixes into the 2.44 branch due to potential instability concerns. It is strongly advised to apply the patch to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gnu Binutils
Affected Vendors
- GNU