CVE-2025-11082

Siemens ProductCERT Advisory SSA-082556

mediumEPSS 0.3%

Description

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

Metrics

Severity
medium
no public PoC known
5.3
Source: nvd-v3
16.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2021-09-26 00:00 UTC
CWE-122, CWE-119

Weakness classes (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →
  • CWE-119Class

    Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

    cwe.mitre.org →

Affected operating systems

  • bsd

    freebsd / freebsd13.2

  • bsd

    freebsd / freebsd13.3

  • bsd

    freebsd / freebsd14.0

  • bsd

    freebsd / freebsd14.1

  • bsd

    netbsd / netbsd

  • linux

    almalinux / almalinux9.0

  • linux

    amazon / amazon_linux2023.0

  • linux

    amazon / amazon_linux

  • linux

    ubuntu / awsbionic

  • linux

    ubuntu / awsjammy

  • linux

    ubuntu / awsnoble

  • linux

    ubuntu / awsresolute

  • linux

    ubuntu / awsxenial

  • linux

    ubuntu / aws-6.8jammy

  • linux

    ubuntu / aws-hwexenial

  • linux

    ubuntu / azurejammy

  • linux

    ubuntu / azurenoble

  • linux

    ubuntu / azureresolute

  • linux

    ubuntu / azurexenial

  • linux

    ubuntu / azure-4.15bionic

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • bitnami

    java-min1.9.0

  • bitnami

    varnish6.1.0

  • bitnami

    varnish7.4.0

  • Dell

    ECS3.8.1.0-3.8.1.7

  • Dell

    NetWorkervProxy 19.14

  • Dell

    PowerScale OneFSNode Firmware Package 14.1

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • Dell

    Secure Connect Gateway< 5.36.00.16

    fixed in 5.36.00.16

  • Dell

    Secure Connect GatewayAppliance <5.32.00.18

  • gnu

    glibc2.35 – 2.37

  • gnu

    glibc

  • gnupg

    libgcrypt1.11.0 – 1.11.3

  • gnupg

    libgcrypt1.12.0 – 1.12.2

  • gnupg

    libgcrypt1.8.8 – 1.10.4

  • hackage

    xz-clib5.6.3

  • hackage

    xz-clib5.6.4

  • hackage

    xz-clib5.8.0

References & sources

Linked CVEs

Show 291 more CVEs
IDCVE-2025-11082