Echo: binutils: security update to 2.45.50.20251201-1

medium Tenable Cloud Security Plugin ID 462609

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in
the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow.
The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The
identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended
to deploy a patch. The code maintainer replied with "[f]ixed for 2.46". (CVE-2025-11083)

Solution

Update the binutils library and its related packages to version 2.45.50.20251201-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-11083

Plugin Details

Severity: Medium

ID: 462609

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.28

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2025-11083

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Threat Score: 1.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/28/2025

Vulnerability Publication Date: 9/27/2025

Reference Information

CVE: CVE-2025-11083

IAVA: 2025-A-0890-S