CVE-2025-7546: Out-of-bounds Write in GNU Binutils
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
AI Analysis
Technical Summary
GNU Binutils version 2.45 contains a vulnerability in the bfd_elf_set_group_contents function of the bfd/elf.c source file that leads to an out-of-bounds write condition. This flaw allows an attacker with local access and low privileges to manipulate data causing memory corruption. The vulnerability has been publicly disclosed, and a patch is available under the commit ID 41461010eb7c79fee7a9d5f6209accdaac66cc6b. The CVSS 4.0 base score is 4.8, indicating a medium severity level with local attack vector and low complexity.
Potential Impact
An attacker with local access and low privileges can exploit this vulnerability to perform an out-of-bounds write, potentially leading to memory corruption. The impact scope includes limited confidentiality, integrity, and availability impacts as indicated by the CVSS vector. No remote exploitation or user interaction is required.
Mitigation Recommendations
A patch identified by commit 41461010eb7c79fee7a9d5f6209accdaac66cc6b is available and should be applied to GNU Binutils 2.45 to remediate this vulnerability. No vendor advisory was provided in the input, so confirm patch availability and installation instructions from the official GNU Binutils project resources.
CVE-2025-7546: Out-of-bounds Write in GNU Binutils
Description
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
CVSS v4.0
Score 4.8medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GNU Binutils version 2.45 contains a vulnerability in the bfd_elf_set_group_contents function of the bfd/elf.c source file that leads to an out-of-bounds write condition. This flaw allows an attacker with local access and low privileges to manipulate data causing memory corruption. The vulnerability has been publicly disclosed, and a patch is available under the commit ID 41461010eb7c79fee7a9d5f6209accdaac66cc6b. The CVSS 4.0 base score is 4.8, indicating a medium severity level with local attack vector and low complexity.
Potential Impact
An attacker with local access and low privileges can exploit this vulnerability to perform an out-of-bounds write, potentially leading to memory corruption. The impact scope includes limited confidentiality, integrity, and availability impacts as indicated by the CVSS vector. No remote exploitation or user interaction is required.
Mitigation Recommendations
A patch identified by commit 41461010eb7c79fee7a9d5f6209accdaac66cc6b is available and should be applied to GNU Binutils 2.45 to remediate this vulnerability. No vendor advisory was provided in the input, so confirm patch availability and installation instructions from the official GNU Binutils project resources.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-12T17:00:15.332Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68743023a83201eaacbf14e0
Added to database: 07/13/2025, 22:16:03 UTC
Last enriched: 07/15/2026, 11:20:24 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 241
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.