A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2025 A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Mar 2025 04:30:00 +0900

Type Values Removed Values Added
First Time appeared Gnu
Gnu binutils
CPEs cpe:2.3:a:gnu:binutils:2.43:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils

Thu, 13 Feb 2025 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 22:45:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 11 Feb 2025 01:45:00 +0900

Type Values Removed Values Added
Description A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Title GNU Binutils ld libbfd.c bfd_malloc memory leak
Weaknesses CWE-401
CWE-404
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:N/A:P'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-02-12T15:46:25.151Z

Reserved: 2025-02-10T07:31:50.638Z

Link: CVE-2025-1150

cve-icon Vulnrichment

Updated: 2025-02-12T15:46:21.647Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-10T17:15:18.517

Modified: 2025-03-11T19:01:04.727

Link: CVE-2025-1150

cve-icon Redhat

Severity : Low

Publid Date: 2025-02-10T16:31:07Z

Links: CVE-2025-1150 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses