/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-11840

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-11840

Severity

5.5

Medium

CVSS V3

Description

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. This patch is called 16357. It is best practice to apply a patch to resolve this issue.

References

Affected packages


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing