CVE-2025-1181

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Feb 11, 2025
CWE ID 119

Summary

CVE-2025-1181 is a newly disclosed critical vulnerability in GNU Binutils 2.43. This issue lies within the _bfd_elf_gc_mark_rsec function of the ld component's bfd/elflink.c file. Exploitation of this flaw leads to memory corruption, enabling an attacker to manipulate the system remotely. The complexity of an attack is relatively high, and its exploitation is considered difficult. However, the exploit has already been made public, increasing the potential risk. To mitigate this vulnerability, it is recommended to apply the patch with the commit ID 931494c9a89558acb36a03a340c01726545eef24.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share