CVE-2025-0840 is a high-severity stack-based buffer overflow vulnerability affecting GNU Binutils up to version 2.43, specifically within the disassemble_bytes function of objdump.c. This flaw allows for remote attack, potentially leading to high impact on confidentiality, integrity, and availability. While the attack complexity and exploitability are rated as difficult, public exploit disclosure exists. There is currently no evidence of active exploitation, nor significant community discussion or media coverage, and no known Metasploit, Nuclei, or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.44CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025binutils: GNU Binutils objdump.c disassemble_bytes stack-based overflow
Jan 29, 2025GNU Binutils objdump.c disassemble_bytes stack-based overflow
Jan 14, 2025