
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11840 is an out-of-bounds read vulnerability in GNU Binutils 2.45, specifically within the vfinfo function in the ldmisc.c file. The vulnerability was disclosed on October 16, 2025, and affects GNU Binutils version 2.45, as well as Microsoft's CBL-2 binutils 2.37-17 and AZL3 binutils 2.41-9 packages (Red Hat Advisory, Red Hat Bugzilla). It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 1.9 (Low) (Red Hat Advisory).
The root cause is improper restriction of memory buffer operations (CWE-119) leading to an out-of-bounds read (CWE-125) in the vfinfo function within ldmisc.c of the GNU Binutils linker. An attacker can trigger this flaw by manipulating input processed by the affected function, causing the program to read memory beyond the intended buffer boundaries. Exploitation requires local access and low-level privileges, with no user interaction needed. A public proof-of-concept exploit and a patch (identified as patch 16357) are both available via the GNU Binutils bug tracker (Red Hat Bugzilla, Sourceware Bugzilla).
Successful exploitation of this vulnerability can cause a denial of service (availability impact: High under CVSS v3.1) by crashing the affected Binutils process through an out-of-bounds memory read. There is no direct impact on confidentiality or integrity of data. The scope is limited to the local system, and the vulnerability does not facilitate lateral movement or significant data exposure (Red Hat Advisory).
A public proof-of-concept exploit is available via the Sourceware bug tracker (attachment ID 16351), and the vulnerability has been publicly disclosed since October 2025 (Sourceware Bugzilla, Sourceware PoC). There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
vfinfo function within ldmisc.c when processed by the linker (ld) or related Binutils tools.ld) against the crafted input as a low-privileged local user, causing the vfinfo function to read memory outside the intended buffer bounds.ld, objdump, or other GNU Binutils processes, particularly during linking operations./var/log/syslog, dmesg) showing segfault or abnormal termination signals from Binutils executables.Apply the upstream patch identified as patch 16357, available via the Sourceware Bugzilla tracker (Sourceware Bugzilla). Ubuntu has released a security notice (USN-7899-1) addressing this and related Binutils vulnerabilities (Ubuntu Advisory). Fedora has also issued updates for mingw-binutils. As a general workaround, restrict local system access and apply the principle of least privilege to limit who can execute Binutils tools. Organizations using Microsoft's CBL-2 or AZL3 packages should consult the Microsoft Security Response Center for applicable updates (Microsoft MSRC).
Red Hat has tracked this vulnerability as low severity and priority in their Bugzilla system, with no immediate patch planned for their distributions at time of disclosure (Red Hat Bugzilla). The Yocto Project security mailing list has discussed the issue across multiple messages, indicating awareness in the embedded Linux community. No significant social media commentary or notable researcher statements have been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."