Clarification on CVE-2025-11081 impact for Binutils 2.40
Siddhesh Poyarekar
siddhesh@gotplt.org
Tue Nov 4 11:39:25 GMT 2025
On 2025-11-03 10:12, Dora, Sunil Kumar via Binutils wrote:
> * Since the vulnerable code path (the unguarded elf_section_type check
> for SHT_GNU_SFRAME) was added in 2.45, our assumption is that 2.40
> does not include that path and therefore isn’t affected by this crash.
Please review the binutils security policy (SECURITY.txt), there's no
vulnerability here. This is an artifact of gamification of CVEs, with
researchers trying to get credited on vulnerabilities by submitting
reports to automated CNAs and bypassing human reviews.
Sid
More information about the Binutils
mailing list