CVE-2025-1152

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Feb 10, 2025
CWE ID 404
CWE ID 401

Summary

CVE-2025-1152 is a recently disclosed vulnerability affecting GNU Binutils 2.43. The issue lies within the xstrdup function of the ld component, resulting in a memory leak. This issue can be exploited remotely, but the complexity of an attack is reportedly high and exploitability is deemed difficult. The code maintainer has acknowledged the issue but has not yet committed the necessary fixes to the 2.44 branch, citing potential instability. It is strongly advised to apply the patch to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share