{"id":"CVE-2025-8225","summary":"GNU Binutils DWARF Section dwarf.c process_debug_info memory leak","details":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","modified":"2026-08-28T14:32:50.083685Z","published":"2025-07-27T08:02:06.568Z","related":["SUSE-SU-2025:21195-1","SUSE-SU-2025:21197-1","SUSE-SU-2025:4096-1","openSUSE-SU-2025:15651-1","openSUSE-SU-2025:20150-1"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-401","CWE-404"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8225.json"},"references":[{"type":"WEB","url":"https://www.gnu.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8225.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225"},{"type":"ADVISORY","url":"https://vuldb.com/?id.317813"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.621883"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.317813"},{"type":"FIX","url":"https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gnutools/binutils-gdb","events":[{"introduced":"815d9a14cbbb3b81843f7566222c87fb22e7255d"},{"fixed":"e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4"}],"database_specific":{"extracted_events":[{"introduced":"2.44"},{"last_affected":"2.44"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://sourceware.org/git/binutils-gdb.git","events":[{"introduced":"815d9a14cbbb3b81843f7566222c87fb22e7255d"},{"last_affected":"815d9a14cbbb3b81843f7566222c87fb22e7255d"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:binutils:2.44:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.44"},{"last_affected":"2.44"}],"source":"CPE_STRING"}}],"versions":["2.44","binutils-2_44"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8225.json","vanir_signatures_modified":"2026-08-28T14:32:50Z","vanir_signatures":[{"target":{"file":"binutils/dwarf.c"},"deprecated":false,"digest":{"line_hashes":["165999291295802883329923850898779896356","105014335341139990871164577991028037228","180591887664868412102303276991854685890","162692490956015083006293578593024538322","75468314745270349724627550155628282484","89197783048136794146220913713931563919","332282208896222479544661138100857955575","77575082719107474791585321126464455399"],"threshold":0.9},"id":"CVE-2025-8225-989df07f","signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/gnutools/binutils-gdb@e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4"},{"deprecated":false,"digest":{"function_hash":"310981831396211155408794020530760590478","length":11973},"id":"CVE-2025-8225-b988f82f","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/gnutools/binutils-gdb@e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","target":{"file":"binutils/dwarf.c","function":"process_debug_info"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}