GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds
Vulnerability Description
A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11414
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Yifan Zhang (VulDB User)
References
- https://vuldb.com/?id.327350
- https://vuldb.com/?ctiid.327350
- https://vuldb.com/?submit.665591
- https://sourceware.org/bugzilla/show_bug.cgi?id=33450
- https://sourceware.org/bugzilla/attachment.cgi?id=16361
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703
- https://www.gnu.org/