Bug 2399943 (CVE-2025-11082)

Summary: CVE-2025-11082 binutils: GNU Binutils Linker heap-based overflow
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: crizzo, dymurray, ibolton, jmatthew, jmitchel, jmontleo, kshier, pgaikwad, rjohnson, slucidi, sseago
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A head based buffer overflow flaw has been discovered in GNU bin utilities. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2400262, 2400267, 2400271, 2400273, 2400284, 2400286, 2400288, 2400291, 2400297, 2400300, 2400303, 2400308, 2400311, 2400313, 2400320, 2400326, 2400328, 2400331, 2400334, 2400340, 2400342, 2400346, 2400352, 2400360, 2400363, 2400365, 2400259, 2400282, 2400294, 2400306, 2400316, 2400323, 2400337, 2400350, 2400356, 2400358    
Bug Blocks:    

Description OSIDB Bzimport 2025-09-27 23:01:15 UTC
A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".