Clarification on CVE-2025-11081 impact for Binutils 2.40

Siddhesh Poyarekar siddhesh@gotplt.org
Tue Nov 4 11:39:25 GMT 2025


On 2025-11-03 10:12, Dora, Sunil Kumar via Binutils wrote:
>   * Since the vulnerable code path (the unguarded elf_section_type check
>     for SHT_GNU_SFRAME) was added in 2.45, our assumption is that 2.40
>     does not include that path and therefore isn’t affected by this crash.

Please review the binutils security policy (SECURITY.txt), there's no 
vulnerability here.  This is an artifact of gamification of CVEs, with 
researchers trying to get credited on vulnerabilities by submitting 
reports to automated CNAs and bypassing human reviews.

Sid


More information about the Binutils mailing list