CVE-2025-11840
LOWGNU Binutils - Memory Corruption
Title source: ruleDescription
A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.
References (7)
Scores
CVSS v3
3.3
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-125
CWE-119
Status
published
Affected Products (1)
gnu/binutils
Timeline
Published
Oct 16, 2025
Tracked Since
Feb 18, 2026