CVE-2025-3198 is a problematic memory leak vulnerability affecting GNU Binutils versions 2.43 and 2.44, specifically within the objdump component's display_info function in binutils/bucomm.c. This vulnerability carries a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges, and potentially leading to a denial of service (high impact on availability). While a public exploit has been disclosed, there is no evidence of active exploitation, and it lacks exploit code in common frameworks like Metasploit or ExploitDB, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.43CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.43:*:*:*:*:*:*:* | ||
2.44CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.44:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.