CVE-2025-1149

Publication date 10 February 2025

Last updated 26 September 2025


Ubuntu priority

Cvss 3 Severity Score

3.1 · Low

Score breakdown

Description

A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Read the notes from the security team

Status

Package Ubuntu Release Status
binutils 25.04 plucky Ignored risk of regression
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble Ignored risk of regression
22.04 LTS jammy Ignored risk of regression
20.04 LTS focal Ignored risk of regression
18.04 LTS bionic Ignored risk of regression
16.04 LTS xenial Ignored risk of regression
14.04 LTS trusty Ignored risk of regression

Notes


seth-arnold

binutils isn't safe for untrusted inputs.


elisehdy

As mentioned in the description, backporting this fix has a high chance of causing regressions. In addition, binutils should not be used in an environment with untrusted inputs, this could be considered a bug and not a vulnerability.

Severity score breakdown

Parameter Value
Base score 3.1 · Low
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact Low
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L