CVE-2025-11494

Siemens ProductCERT Advisory SSA-082556

mediumEPSS 0.2%

Description

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.

Metrics

Severity
medium
no public PoC known
4.8
Source: nvd-v4
11.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2021-09-26 00:00 UTC
CWE-125, CWE-119

Weakness classes (CWE)

  • CWE-125Base

    Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →
  • CWE-119Class

    Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

    cwe.mitre.org →

Affected operating systems

  • bsd

    freebsd / freebsd13.2

  • bsd

    freebsd / freebsd13.3

  • bsd

    freebsd / freebsd14.0

  • bsd

    freebsd / freebsd14.1

  • bsd

    netbsd / netbsd

  • linux

    almalinux / almalinux9.0

  • linux

    amazon / amazon_linux2023.0

  • linux

    amazon / amazon_linux

  • linux

    ubuntu / awsbionic

  • linux

    ubuntu / awsjammy

  • linux

    ubuntu / awsnoble

  • linux

    ubuntu / awsresolute

  • linux

    ubuntu / awsxenial

  • linux

    ubuntu / aws-6.8jammy

  • linux

    ubuntu / aws-hwexenial

  • linux

    ubuntu / azurejammy

  • linux

    ubuntu / azurenoble

  • linux

    ubuntu / azureresolute

  • linux

    ubuntu / azurexenial

  • linux

    ubuntu / azure-4.15bionic

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • bitnami

    java-min1.9.0

  • bitnami

    varnish6.1.0

  • bitnami

    varnish7.4.0

  • Dell

    ECS3.8.1.0-3.8.1.7

  • Dell

    NetWorkervProxy 19.14

  • Dell

    PowerScale OneFSNode Firmware Package 14.1

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • Dell

    Secure Connect Gateway< 5.36.00.16

    fixed in 5.36.00.16

  • Dell

    Secure Connect GatewayAppliance <5.32.00.18

  • gnu

    glibc2.35 – 2.37

  • gnu

    glibc

  • gnupg

    libgcrypt1.11.0 – 1.11.3

  • gnupg

    libgcrypt1.12.0 – 1.12.2

  • gnupg

    libgcrypt1.8.8 – 1.10.4

  • hackage

    xz-clib5.6.3

  • hackage

    xz-clib5.6.4

  • hackage

    xz-clib5.8.0

References & sources

Linked CVEs

Show 291 more CVEs
IDCVE-2025-11494