CVE-2025-11839 MEDIUM

CVE-2025-11839: GNU Binutils prdbg.c tg_tag_type return value

Vendor Gnu
Product Binutils
Weakness CWE-252
Published October 16, 2025
Last update May 12, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.

Key dates

02Disclosure timeline

October 16, 2025 CVE published
May 12, 2026 Record updated