CVE-2025-3198 Details
Description
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.
A memory leak vulnerability has been identified in GNU Binutils versions 2.43 and 2.44. The issue arises in the objdump component, specifically within the display_info function of bucomm.c. This vulnerability requires local exploitation.
Users are advised to apply the patch referenced by the commit ID ba6ad3a18cb26b79e0e3b84c39f707535bbc344d.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html | siemens-SADP | |
| https://cert-portal.siemens.com/productcert/html/ssa-265688.html | siemens-SADP | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=32716 | CISA-ADP | Broken Link |
| https://sourceware.org/bugzilla/show_bug.cgi?id=32716 | [email protected] | Broken Link |
| https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0 | [email protected] | Issue Tracking |
| https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d | [email protected] | Broken Link |
| https://vuldb.com/?ctiid.303151 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.303151 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.545773 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.gnu.org/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu binutils | 2.43 2.44 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| May 15, 2025 | Initial Analysis | [email protected] |
| Apr 4, 2025 | CVE Modified | CISA-ADP |
| Apr 4, 2025 | New CVE Received | [email protected] |