« List of all CVEs

CVE-2025-7546

GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write

Published: 7/13/2025 Last updated: 7/14/2025 Reserved: 7/12/2025

A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.

CNA assigner: VulDB (1af790b2-7ee1-4545-860a-a788eba489b5) Requested by: n/a

Metrics

Version Score Severity Vector String
4.0 1.9 Low CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
3.1 4.8 Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
3.0 4.8 Medium CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
2.0 3.4 Low CVSS:2.0/AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Opam packages affected (3)

bap-std clangml conf-binutils

Products affected (1)

Product Vendor Version
Binutils GNU unspecified

References (9)

Credits (1)