CVE-2025-3198

LOW

GNU Binutils 2.43-2.44 - Memory Leak in objdump display_info Function

Title source: llm
STIX 2.1

Description

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

References (9)

Core 9
Core References
Product product
https://www.gnu.org/
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.303151
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.303151
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.545773
Issue Tracking exploit issue-tracking
https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0

Scores

CVSS v3 3.3
EPSS 0.0023
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-401 CWE-404
Status published
Products (4)
gnu/binutils 2.43
gnu/binutils 2.44
GNU/Binutils 2.43
GNU/Binutils 2.44
Published Apr 04, 2025
Tracked Since Feb 18, 2026