A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
History

Tue, 11 Mar 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu binutils
CPEs cpe:2.3:a:gnu:binutils:2.43:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils

Wed, 12 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 10 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
Title GNU Binutils ld libbfd.c bfd_malloc memory leak
Weaknesses CWE-401
CWE-404
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:N/A:P'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-02-10T16:31:07.343Z

Updated: 2025-02-12T15:46:25.151Z

Reserved: 2025-02-10T07:31:50.638Z

Link: CVE-2025-1150

cve-icon Vulnrichment

Updated: 2025-02-12T15:46:21.647Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-10T17:15:18.517

Modified: 2025-03-11T19:01:04.727

Link: CVE-2025-1150

cve-icon Redhat

Severity : Low

Publid Date: 2025-02-10T16:31:07Z

Links: CVE-2025-1150 - Bugzilla