Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:23306

Опубликовано: 20 дек. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: binutils security update

The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.

Security Fix(es):

  • binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11082)

  • binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
binutilsx86_6458.el10_1.2binutils-2.41-58.el10_1.2.x86_64.rpm
binutils-goldx86_6458.el10_1.2binutils-gold-2.41-58.el10_1.2.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
29 дней назад

ELSA-2025-23306: binutils security update (MODERATE)

CVSS3: 7.8
redos
2 месяца назад

Множественные уязвимости binutils

CVSS3: 5.3
ubuntu
4 месяца назад

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

CVSS3: 5.3
nvd
4 месяца назад

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

CVSS3: 5.3
msrc
4 месяца назад

GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow