A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
CVSS Details
- CVSS 4.0 Base Score: 1.9 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade golang-miscUpgrade golang-srcUpgrade golangUpgrade golang-sharedUpgrade golang-binUpgrade golang-docsUpgrade golang-tests | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade binutils-develUpgrade binutils-debugsourceUpgrade binutils-gprofng-debuginfoUpgrade binutils-gprofngUpgrade binutilsUpgrade binutils-debuginfo | Sep 30, 2025 | Jul 13, 2025 |
| Debian | — | No solution exists | Jul 15, 2025 | Jul 13, 2025 |
| Redhat_linux | — | No solution exists | Jul 15, 2025 | Jul 13, 2025 |
| Ubuntu | — | Upgrade binutilsUpgrade binutils-multiarch | Oct 30, 2025 | Oct 29, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Jul 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub