suse · CVE-2025-3198

Quick triage

Priority: medium Published: 2025-04-07 23:15:07 UTC Updated: 2026-04-16 14:37:19 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-3198 severity moderate: SUSE including 387 source package names (0.23.1-11.83:binutils-2.45-150100.7.57.1, 0.23.1-11.83:libctf-nobfd0-2.45-150100.7.57.1, …), 1288 product×package rows across 231 product lines (Container bci/spack, Container containers/open-webui, … (231 product lines)): Fixed 1049, Known Affected 231, First Fixed 7, Known Not Affected 1.

Description:

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

cvelogic Threat Intelligence