Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:0108

Опубликовано: 09 янв. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: gcc-toolset-15-binutils security update

Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying call graph profile data), ld (the GNU linker), nm (for listing symbols from object files), objcopy (for copying and translating object files), objdump (for displaying information from object files), ranlib (for generating an index for the contents of an archive), readelf (for displaying detailed information about binary files), size (for listing the section sizes of an object or archive file), strings (for listing printable strings from files), strip (for discarding symbols), and addr2line (for converting addresses to file and line).

Security Fix(es):

  • binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
gcc-toolset-15-binutils-gprofngx86_647.el10_1.1gcc-toolset-15-binutils-gprofng-2.44-7.el10_1.1.x86_64.rpm
gcc-toolset-15-binutils-goldx86_647.el10_1.1gcc-toolset-15-binutils-gold-2.44-7.el10_1.1.x86_64.rpm
gcc-toolset-15-binutilsx86_647.el10_1.1gcc-toolset-15-binutils-2.44-7.el10_1.1.x86_64.rpm
gcc-toolset-15-binutils-develx86_647.el10_1.1gcc-toolset-15-binutils-devel-2.44-7.el10_1.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

CVSS3: 5.3
nvd
4 месяца назад

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

CVSS3: 5.5
msrc
4 месяца назад

GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow

CVSS3: 5.3
debian
4 месяца назад

A vulnerability has been found in GNU Binutils 2.45. The affected elem ...

rocky
10 дней назад

Moderate: gcc-toolset-14-binutils security update