Echo: binutils: security update to 2.45.50.20251201-1

medium Tenable Cloud Security Plugin ID 463899

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the
file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed
locally. The exploit has been made available to the public and could be used for attacks. This patch is
called 16357. It is best practice to apply a patch to resolve this issue. (CVE-2025-11840)

Solution

Update the binutils library and its related packages to version 2.45.50.20251201-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-11840

Plugin Details

Severity: Medium

ID: 463899

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.12

CVSS v2

Risk Factor: Low

Base Score: 1.7

Temporal Score: 1.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P

CVSS Score Source: CVE-2025-11840

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Threat Score: 1.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/16/2025

Vulnerability Publication Date: 10/16/2025

Reference Information

CVE: CVE-2025-11840

IAVA: 2025-A-0809-S