CVE-2025-1152
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Feb 10, 2025
CWE ID 404
CWE ID 401
Summary
CVE-2025-1152 is a recently disclosed vulnerability affecting GNU Binutils 2.43. The issue lies within the xstrdup function of the ld component, resulting in a memory leak. This issue can be exploited remotely, but the complexity of an attack is reportedly high and exploitability is deemed difficult. The code maintainer has acknowledged the issue but has not yet committed the necessary fixes to the 2.44 branch, citing potential instability. It is strongly advised to apply the patch to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Gnu Binutils
Affected Vendors
- GNU