CVE-2025-7545 is a heap-based buffer overflow vulnerability in the copy_section function of binutils/objcopy.c within GNU Binutils 2.45. This flaw allows a local attacker to achieve high confidentiality, integrity, and availability impacts. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and no readily available exploit modules or significant community discussion have been observed. A patch (08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944) is available to remediate this high-severity vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.45CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.45:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.