CVE-2025-11494: GNU Binutils
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.
Affected products
- GNU Binutils: version 2.45 only
Published 2025-10-08. Last modified 2026-10-08.