CVE-2025-5244: Memory Corruption in GNU Binutils
A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.
AI Analysis
Technical Summary
This vulnerability affects the elf_gc_sweep function in the bfd/elflink.c file of the ld component in GNU Binutils versions up to 2.44. The issue results in memory corruption due to improper manipulation within this function. The attack vector is local with low complexity and no user interaction required. The CVSS 4.0 base score is 4.8, reflecting medium severity. The vulnerability is fixed in version 2.45.
Potential Impact
Successful exploitation can lead to memory corruption on the affected system, potentially causing crashes or undefined behavior. The attack requires local access and privileges, limiting remote exploitation. No known exploits are currently observed in the wild.
Mitigation Recommendations
Upgrade GNU Binutils to version 2.45 or later, which contains the official fix for this vulnerability. Since this is a local attack vector, restricting local access and privileges can also reduce risk.
CVE-2025-5244: Memory Corruption in GNU Binutils
Description
A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.
CVSS v4.0
Score 4.8medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects the elf_gc_sweep function in the bfd/elflink.c file of the ld component in GNU Binutils versions up to 2.44. The issue results in memory corruption due to improper manipulation within this function. The attack vector is local with low complexity and no user interaction required. The CVSS 4.0 base score is 4.8, reflecting medium severity. The vulnerability is fixed in version 2.45.
Potential Impact
Successful exploitation can lead to memory corruption on the affected system, potentially causing crashes or undefined behavior. The attack requires local access and privileges, limiting remote exploitation. No known exploits are currently observed in the wild.
Mitigation Recommendations
Upgrade GNU Binutils to version 2.45 or later, which contains the official fix for this vulnerability. Since this is a local attack vector, restricting local access and privileges can also reduce risk.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-05-27T08:07:03.937Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6835ba7c182aa0cae2128088
Added to database: 05/27/2025, 13:13:32 UTC
Last enriched: 07/15/2026, 11:29:21 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.