CVE-2025-7545

MEDIUM

GNU Binutils <2.45 - Heap-based Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-7545. PoCs published by alxsourin.

AI-analyzed exploit summary This repository contains a functional PoC for CVE-2025-7545, demonstrating a heap-buffer-overflow in Binutils' objcopy when processing firmware files. The setup script configures a vulnerable environment and includes tools to trigger the vulnerability via crafted firmware inputs.

Description

A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.

Exploits (1)

nomisec WORKING POC
by alxsourin · poc
https://github.com/alxsourin/Firmware-CVE-2025-7545

This repository contains a functional PoC for CVE-2025-7545, demonstrating a heap-buffer-overflow in Binutils' objcopy when processing firmware files. The setup script configures a vulnerable environment and includes tools to trigger the vulnerability via crafted firmware inputs.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Binutils (objcopy) version 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944^1
No auth needed
Prerequisites: Vulnerable Binutils version · Ability to execute objcopy with crafted firmware files
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.316243
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.316243
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.614355
Product product
https://www.gnu.org/

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 16.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-122
Status published
Products (2)
gnu/binutils 2.45
GNU/Binutils 2.45
Published Jul 13, 2025
Tracked Since Feb 18, 2026