Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 106 articles for you...
219

AlmaLinux 8 RLSA-2026-3637 python3-urllib3 Major Security Notification

Moderate: gcc-toolset-14-binutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2627", "synopsis": "Moderate: gcc-toolset-14-binutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for gcc-toolset-14-binutils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying call graph profile data), ld (the GNU linker), nm (for listing symbols from object files), objcopy (for copying and translating object files), objdump (for displaying information from object files), ranlib (for generating an index for the contents of an archive), readelf (for displaying detailed information about binary files), size (for listing the section sizes of an object or archive file), strings (for listing printable strings from files), strip (for discarding symbols), and addr2line (for converting addresses to file and line).\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2399948", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948", "description": ""}], "cves": [{"name": "CVE-2025-11083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11083", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-02-17T09:03:08.291679Z", "rpms": {"Rocky Linux 8": {"nvras":["gcc-toolset-14-binutils-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-0:2.41-4.el8_10.1.src.rpm", "gcc-toolset-14-binutils-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-debuginfo-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-debuginfo-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-devel-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-devel-0:2.41-4.el8_10.1.i686.rpm", "gcc-toolset-14-binutils-devel-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-gold-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-gold-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-gold-debuginfo-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-gold-debuginfo-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-gprofng-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-gprofng-0:2.41-4.el8_10.1.x86_64.rpm", "gcc-toolset-14-binutils-gprofng-debuginfo-0:2.41-4.el8_10.1.aarch64.rpm", "gcc-toolset-14-binutils-gprofng-debuginfo-0:2.41-4.el8_10.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The gcc-toolset-14-binutils security update is crucial for Rocky Linux 8 users, addressing known vulnerabilities.. gcc-toolset update, Rocky Linux security, binutils patch. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2026 Rocky Linux
217

Oracle Linux 10: Moderate binutils Memory Fix ELSA-2025-23306

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2025-23306 http://linux.oracle.com/errata/ELSA-2025-23306.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: binutils-2.41-58.0.1.el10_1.2.x86_64.rpm binutils-devel-2.41-58.0.1.el10_1.2.x86_64.rpm binutils-gold-2.41-58.0.1.el10_1.2.x86_64.rpm aarch64: binutils-2.41-58.0.1.el10_1.2.aarch64.rpm binutils-devel-2.41-58.0.1.el10_1.2.aarch64.rpm binutils-gold-2.41-58.0.1.el10_1.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/binutils-2.41-58.0.1.el10_1.2.src.rpm Related CVEs: CVE-2025-11082 CVE-2025-11083 Description of changes: [2.41-58.0.1.2] - Forward-port Oracle patches to 2.41-58.2 - CVE-2025-11082 - CVE-2025-11083 Reviewed-by: David Faust Oracle history: September-29-2025 David Faust - 2.41-58.0.1 - Forward-port Oracle patches to 2.41-58. Reviewed-by: Jose E. Marchesi August-29-2025 Bruce McCulloch - 2.41-57.0.1 - Forward-port Oracle patches to 2.41-57. Reviewed-by: Jose E. Marchesi Jun-04-2025 Bruce McCulloch - 2.41-53.0.3 - Add binutils-orabug-38018827.patch. - Fix ctf_dict_open clobbering errno. - Backport of upstream commit: - 14303d6295e libctf: archive, open: when opening, always set errp to something. - [Orabug: 38018827] - Add binutils-orabug-38018828.patch. - In kernel links, properly hide CTF types only if conflicting. - Backport of upstream commits: - 75e514cfa56 Revert "libctf: fix linking of non-root-visible types" - 002957be18e libctf: dedup: improve hiding of conflicting types in the same dict - [Orabug: 38018828] Reviewed-by: Jose E. Marchesi Reviewed-by: Nick Alcock Reviewed-by: Elena Zannoni May-28-2025 Vladimir Mezentsev - 2.41-53.0.2 - Backported updates for gprofng. Reviewed-by: Bruce McCulloch April-02-2025 Bruce McCulloch - 2.41-53.0.1 - Merge Oracle patches to 2.41-53. Reviewed-by: Jose E. Marchesi November-28-2024 Nick Alcock - 2.41-45.0.1 - Latest CTF changes from upstream - add ctf_dict_set_flag, ctf_lookup_enumerator, ctf_lookup_enumerator_next, ctf_arc_lookup_enumerator_next; consider enums with differing enumerators to be conflicting - add documentation to ctf-api.h - allow modification of ctf_opened dicts and opening of foreign- endian older dicts - looking up types by name prefers non-bitfields if possible - bugfixes to parent propagation, rewriting of existing dicts, ctf_archive_count, CU-mapped links, and dumping and linking of non-root-visible types. - fix a bunch of small leaks and one big one (on ctf_open error) - fix a write into freed memory after ctf_rollback and writeout - internal improvements to serialization, name lookup, symbol lookup, string handling, and more - explicitly disable zstd support (enabling requires addition of zstd to the .so scripts) [2.41-58.2] - Fix a potential illegal memory access when linking a corrupt input file. (RHEL-126875) [2.41-58.1] - Fix a potential illegal memory access when linking a corrupt input file. (RHEL-125206) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated binutils for Oracle Linux 10 addresses moderate memory access issues related to CVE-2025-11082.. Oracle Linux 10, binutils updates, memory access issues, ELSA-2025-23306. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 20, 2025 Important Oracle
217

Oracle Linux 9 ELSA-2025-23343 binutils Moderate Memory Access Warning

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2025-23343 http://linux.oracle.com/errata/ELSA-2025-23343.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: binutils-2.35.2-67.0.1.el9_7.1.i686.rpm binutils-2.35.2-67.0.1.el9_7.1.x86_64.rpm binutils-devel-2.35.2-67.0.1.el9_7.1.i686.rpm binutils-devel-2.35.2-67.0.1.el9_7.1.x86_64.rpm binutils-gold-2.35.2-67.0.1.el9_7.1.x86_64.rpm aarch64: binutils-2.35.2-67.0.1.el9_7.1.aarch64.rpm binutils-devel-2.35.2-67.0.1.el9_7.1.aarch64.rpm binutils-gold-2.35.2-67.0.1.el9_7.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/binutils-2.35.2-67.0.1.el9_7.1.src.rpm Related CVEs: CVE-2025-11083 Description of changes: [2.35.2-67.0.1.1] - Merge Oracle patches to 2.35.2-67.1. - CVE-2025-11083 - Reviewed-by: David Faust Oracle history: September-24-2025 Bruce McCulloch - 2.35.2-67.0.1 - Merge Oracle patches to 2.35.2-66. - Reviewed-by: Jose E. Marchesi September-5-2025 Bruce McCulloch - 2.35.2-66.0.1 - Merge Oracle patches to 2.35.2-66. - Reviewed-by: Jose E. Marchesi August-4-2025 Bruce McCulloch - 2.35.2-65.0.1 - Merge Oracle patches to 2.35.2-65. - Reviewed-by: Jose E. Marchesi April-10-2025 Bruce McCulloch - 2.35.2-63.0.1 - Merge Oracle patches to 2.35.2-63. - Reviewed-by: Jose E. Marchesi January-10-2025 Bruce McCulloch - 2.35.2-55.0.1 - Forward-port Oracle patches to 2.35.2-55. - Refresh CTF patches March-27-2024 Jose E. Marchesi - 2.35.2-43.0.1 - Forward-port Oracle patches to 2.35.2-43. March-07-2024 Jose E. Marchesi - 2.35.2-42.0.2.1 - Do not set version info on unversion symbols. (RHEL-22601) - Reviewed by: Elena Zannoni February-06-2024 Nick Alcock - 2.35.2-42.0.2 - Refresh CTF patches from upstream (2.42). - Fix more cases where operations on child dicts could leave errors on the parent, this timeassociated with CTF dict creation (upstream PR libctf/30985). - Fix the cu-mapped link feature (not exposed by GNU ld) to use only the last mapping provided for a given translation unit, rather than a random mix of first and last - Fix dependencies of libctf.so and libctf-nobfd.so to cite the libraries the code actually depends on. (Fixes observed link problems with libctf-nobfd.so needing extra libraries on the link line versus upstream: libctf.so changes done purely for consistency.) - Add upstream commit 2e93abb858ae, allowing NONE relocs against local absolute symbols on x86-64. (Upstream PR ld/31047). October-10-2023 Jose E. Marchesi - 2.35.2-42.0.1 - Forward-port Oracle patches to 2.35.2-42. August-04-2023 Nick Alcock - 2.35.2-37.0.2 - Refresh CTF patches from upstream. - Avoid spurious corruption error with symtypetab section emitted by old OL8 GCCs - Various obscure install-time linking problems - Make objdump/readelf --ctf parameter optional; make objdump --ctf-parent take a CTF member name, not a section name - Improve dumping of types when some types elicit a libctf error - Put functions as well as variables in the (misnamed) CTF variable section - Improve handling of various forms of corrupted CTF input. - Fix errors in comments in and - Make CTF dicts reproducible even when conflicting types are seen - Prevent corruption of output when linking multiple object files derived from the same source - Minor compiler warning and portability fixes - Fix (unlikely) crash-inducing uninitialized memory access and wild pointer overwrite when linking - Fix the reported offsets of fields within unnamed structs/unions [Orabug: 35191322] - Fix a number of places where operations carried out on child dicts that errored were producing errors on the parent, not the child, so the caller never noticed them March-28-2023 Guillermo E. Martinez - 2.35.2-37.0.1 -Forward-port Oracle patches from 2.35.2-24.0.1 - Reviewed-by: Jose E. Marchesi April-25-2022 David Faust - 2.35.2-17.0.1 - Forward-port Oracle patches from 2.35.2-9.0.1 to 2.35.2-17.0.1 - Reviewed-by: Jose E. Marchesi November-23-2021 David Faust - 2.35.2-9.0.1 - Enable libctf - Backport all CTF improvements since 2.35.2 release, upstream commits: 6ab5b6d0f3a libctf, lookup: fix bounds of pptrtab lookup e695879142a libctf, testsuite: fix various warnings in tests b62d5edd0a5 libctf: fix handling of CTF symtypetab sections emitted by older GCC ea9c2009115 libctf: try several possibilities for linker versioning flags bef9ef8ca0f libtool.m4: fix nm BSD flag detection bc4b1401129 libtool.m4: augment symcode for Solaris 11 7d53105d6ed libctf: link against libiberty before linking in libbfd or libctf-nobfd ae064303efe libctf, ld: fix test results for upstream GCC 49da556c658 libctf, include: support an alternative encoding for nonrepresentable types 8592be8c7d3 ld: do not rely on the exact size of the CTF symtypetabs in test results 8f7b22ea2a9 libctf: fix ELF-in-BFD checks in the presence of ASAN 15131809c23 libctf: fix memory leak in a test 0bd65ce30a8 libctf: don't dereference out-of-bounds locations in the qualifier hashtab 5226ef61131 libctf: make ctf_bfdopen_ctfsect a debugger entry point 86f64bf43f7 libctf, serialize: functions with no args have a NULL dtd_vlen 24c877f9b19 include: always do unsigned left-shift in CTF_SET_STID 485170cdb1b libctf, dump: do not emit size or alignment if it would error e93388417c1 Provide an inline startswith function in bfd.h 69a284867c7 libctf: support encodings for enums e4c78f303df libctf: a couple of small error-handling fixes d7b1416ef2c libctf: types: unify code dealing with small-vs-large struct members 08c428aff4a libctf: eliminate dtd_u, part 5: structs / unions 77d724a7ecd libctf: eliminate dtd_u, part 4: enums 986e9e3aa03 libctf: do not corruptstrings across ctf_serialize 2a05d50e90c libctf: don't lose track of all valid types upon serialization 755ba58ebef Add install dependencies for ld -> bfd and libctf -> bfd 81982d20fac libctf: eliminate dtd_u, part 3: functions 534444b1ee1 libctf: eliminate dtd_u, part 2: arrays 7879dd88efd libctf: eliminate dtd_u, part 1: int/float/slice eefe721eadf libctf: fix GNU style for do {} while b9a964318a7 libctf: split up ctf_serialize 01cbfcba4bc libctf: fix comment above ctf_dict_t bf4c3185a5a libctf: split serialization and file writeout into its own file 087945261c7 libctf: fix some tabdamage and move some code around 211bcd01333 bfd, ld, libctf: skip zero-refcount strings in CTF string reporting 8e7e446446b libctf: free ctf_dynsyms properly cf6a0b989a5 libctf: fix signed/unsigned comparison confusion 4659554b280 libctf: minor error-handling fixes f5060e56338 libctf: add a deduplicator-specific type mapping table 478c04a55ee libctf: remove reference to "unconflicted link mode". 8915c559d40 libctf, include: remove the nondeduplicating CTF linker fd12633780a libctf: fix ChangeLog date ac36e134d96 libctf: reimplement many _iter iterators in terms of _next eaa2913a7ac libctf: ctf_archive_next should set the parent name consistently 93993f67849 libctf AC_CANONICAL_TARGET f4f60336dae libctf, include: find types of symbols by name 758f590744b libctf: add missing header in BFD ELF check cbd8f5bbcc8 libctf: require a Tcl capable of try/catch to run tests 95148614026 bfd, opcodes, libctf: support --with-included-gettext ee87f50b8d2 libctf: always name nameless types "", never NULL 5dacd11ddcf libctf: fix uninitialized variable in symbol serialization error handling caa170493e8 libctf: prohibit nameless ints, floats, typedefs and forwards 78f28b89e8c libctf: rip out dead code handling typedefs with no name 35a01a04544 libctf, ld: fix symtypetab and var section population under ld -r f04ce15e831 ld:depend on libctf 26503e2f5ea libctf, create: fix ctf_type_add of structs with unnamed members e05a3e5a491 libctf: lookup_by_name: do not return success for nonexistent pointer types 0814dbfbfcc libctf, testsuite: adjust for real return type of ctf_member_count 70d3120f322 libctf, testsuite: don't run without a suitable compiler b4b6ea46807 libctf, ld: fix formatting of forwards to unions and enums abe4ca69a11 libctf: fix lookups of pointers by name in parent dicts 8769046e5a9 libctf: remove outdated comment about parent dict importing 6c3a38777b3 libctf, include: support unnamed structure members better abed0b0718a libctf: warn about information loss because of unreleased format changes 9bc769718db libctf: new test of enum lookups with the _next iterator c59e30ed172 libctf: new testsuite 1038406a8f6 libctf: rip out BFD_DEPENDENCIES / BFD_LIBADD 37002871ac2 libctf, ld: dump enums: generally improve dump formatting ffeece6ac2d libctf, ld: prohibit getting the size or alignment of forwards 91e7ce2fd7b libctf, ld: more dumper improvements 57f97d0e6dd libctf, ld: CTF dumper changes for consistency b09ad6eae98 libctf: do not print array declarators backwards a7c23ac9317 In libctf, make AC_CONFIG_MACRO_DIR consistent with ACLOCAL_AMFLAGS e8cda209052 libctf: Pass format argument to asprintf 96c61be508f binutils: readelf: support CTF dicts with non-native-endian symtabs 53651de80f8 libctf, include: support foreign-endianness symtabs with CTF ef21dd3bcff libctf: do not crash when CTF symbol or variable linking fails 8f235c90a28 libctf: error-handling fixes 97a2a623d01 libctf, include: add ctf_getsymsect and ctf_getstrsect 2c78e92523a libctf, include: CTF-archive-wide symbol lookup 0e28ade476e libctf, ld: properly deduplicate function types 0ad70c536ab ld, ctf: new and adjusted CTF tests due to func info / object data sections 4665e895c37 libctf: adjust dumper for symtypetab changes 1136c379718 libctf: symboltype linking support 3d16b64e28a bfd, include, ld, binutils, libctf: CTF should use the dynstr/sym 83d59285d54 objdump, readelf: Report errors from CTF archive iteration ae41200ba80 libctf, include, binutils, gdb: rename CTF-opening functions 139633c307e libctf, include, binutils, gdb, ld: rename ctf_file_t to ctf_dict_t 0d01fbe64f6 Remove libctf/mkerrors.sed 5e9b84f7a2e binutils, ld: dequote libctf error messages 926c9e76657 libctf, binutils, include, ld: gettextize and improve error handling 555adca2e3b libctf: compilation failure on MinGW due to missing errno values 50500ecfefd libctf: compilation failure on MinGW due to missing errno values 8c419a91d76 libctf: fixes for systems on which sizeof (void *) > sizeof (long) 734c894234e libctf: fix isspace casts 4533ed564d6 libctf, binutils: fix big-endian libctf archive opening 62cdd7b18fc ld, testsuite: do not run CTF tests at all on non-ELF for now fa03171fb46 ld: do not produce one empty output .ctf section for every input .ctf 7cdfc3462fb ld, testsuite: only run CTF tests when ld and GCC support CTF b1b33524ad3 ld: new CTF testsuite 0b884151088 binutils, testsuite: allow compilation before doing run_dump_test 5dba6f05b7b ld: new options --ctf-variables and --ctf-share-types f320bba50ff ld: Reformat CTF errors into warnings. 3dd6b890b4e binutils: objdump: ctf: drop incorrect linefeeds 662df3c3f14 libctf, link: tie in the deduplicating linker e3e8411bec4 libctf, link: add CTF_LINK_OMIT_VARIABLES_SECTION 0f0c11f7fc9 libctf, dedup: add deduplicator a9b98702066 libctf, dedup: add new configure option --enable-libctf-hash-debugging 1f2e8b5b87d libctf: add SHA-1 support for libctf 6dd2819ffc2 libctf, link: add the ability to filter out variables from the link 19d4b1addca libctf, link: fix spurious conflicts of variables in the variable section 5f54462c6ab libctf, link: redo cu-mapping handling e3f17159e26 libctf, link: fix ctf_link_write fd leak 8d2229ad1e7 libctf, link: add lazy linking: clean up input members: err/warn cleanup e148b730131 libctf: drop error-prone ctf_strerror 1fa7a0c24e7 libctf: sort out potential refcount loops 3166467b00a libctf: rename the type_mapping_key to type_key 43a61d7d3e6 libctf: check for vasprintf ac2ff760303 libctf, archive: fix bad error message d50c08025d4 libctf, open: fix opening CTF in binaries with no symtab 70447401740 libctf, dump: fix slice dumping 8e795b46f58 libctf, dump: migrate towards dumping errors rather than truncation b255b35feb8 libctf, decl: avoid leaks of the formatted string on error c6e9a1e576c libctf, types: enhance ctf_type_aname to print function arg types 8b37e7b63ed libctf, ld, binutils: add textual error/warning reporting for libctf b7190c821e5 libctf, types: ensure the emission of ECTF_NOPARENT ec388c16cd4 libctf: error out on corrupt CTF with invalid header flags 67d4cc671b7 libctf: pass the thunk down properly when wrapping qsort_r e28591b3dfc libctf, next, hash: add dynhash and dynset _next iteration 688d28f6214 libctf, next: introduce new class of easier-to-use iterators 2399827bfa1 libctf: add ctf_ref 9850ce4d7bb libctf: add ctf_forwardable_kind 2c9ca36be17 libctf: move existing inlines into ctf-inlines.h 77648241384 libctf, hash: introduce the ctf_dynset a49c6c6a656 libctf, hash: save per-item space when no key/item freeing function 5ceee3dba34 libctf, hash: improve insertion of existing keys into dynhashes 809f6eb3321 libctf: add new dynhash functions 469e75b621f libctf: fix __extension__ with non-GNU C compilers 9c23dfa5aa4 libctf: add ctf_archive_count e0325e2cede libctf: add ctf_member_count 9b15cbb7891 libctf: add ctf_type_kind_forwarded 01d9317436c libctf: add ctf_type_name_raw 5ec7465fec8 libctf: having debugging enabled is unlikely 601e455b758 libctf, archive: stop ctf_arc_bufopen triggering crazy unmaps 96e3ec29664 libctf, types: ints, floats and typedefswith no name are invalid 502e838ed96 libctf, types: support slices of anything terminating in an int dd987f00430 libctf, create: empty dicts are dirty to start with f47ca311356 libctf, create: fix addition of anonymous struct/union members ab769488e75 libctf, create: member names of "" and NULL should be the same 2484ca436ac libctf, open: drop unnecessary historical wart around forwards 437061996d8 libctf, types: allow ctf_type_reference of dynamic slices 9943fa3a732 libctf, create: add explicit casts for variables' and slices' types afd78bd6f0a libctf, create: do not corrupt function types' arglists at insertion time 2361f1c8591 libctf, create: support addition of references to the unimplemented type 7eea9d3bdb0 libctf: restructure error handling to reduce relocations b64751cf0bc include, libctf: typo fixes df16e041dea Fix problems in CTF handling code exposed by the Coverity static analysis tool. - Reviewed-by: Jose E. Marchesi [2.35.2-67.1] - Fix a potential illegal memory access when linking a corrupt input file. (RHEL-126883) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 Security Advisory ELSA-2025-23343 for binutils addresses a moderate threat of memory access issues.. Oracle Linux, binutils, security advisory, memory access, updates. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2025 Oracle
219

Rocky Linux 10 RLSA-2025-23312 Gcc Notable Risk Weakness Discovered

Moderate: binutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23306", "synopsis": "Moderate: binutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for binutils.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11082)\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2399943", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399943", "description": ""}, {"ticket": "2399948", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948", "description": ""}], "cves": [{"name": "CVE-2025-11082", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11082", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-122"}, {"name": "CVE-2025-11083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11083", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-122"}], "references": [], "publishedAt": "2025-12-20T09:08:07.642679Z", "rpms": {"Rocky Linux 10": {"nvras": ["binutils-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-0:2.41-58.el10_1.2.ppc64le.rpm","binutils-0:2.41-58.el10_1.2.s390x.rpm", "binutils-0:2.41-58.el10_1.2.src.rpm", "binutils-0:2.41-58.el10_1.2.x86_64.rpm", "binutils-debuginfo-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-debuginfo-0:2.41-58.el10_1.2.ppc64le.rpm", "binutils-debuginfo-0:2.41-58.el10_1.2.s390x.rpm", "binutils-debuginfo-0:2.41-58.el10_1.2.x86_64.rpm", "binutils-debugsource-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-debugsource-0:2.41-58.el10_1.2.ppc64le.rpm", "binutils-debugsource-0:2.41-58.el10_1.2.s390x.rpm", "binutils-debugsource-0:2.41-58.el10_1.2.x86_64.rpm", "binutils-devel-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-devel-0:2.41-58.el10_1.2.ppc64le.rpm", "binutils-devel-0:2.41-58.el10_1.2.s390x.rpm", "binutils-devel-0:2.41-58.el10_1.2.x86_64.rpm", "binutils-gold-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-gold-0:2.41-58.el10_1.2.ppc64le.rpm", "binutils-gold-0:2.41-58.el10_1.2.s390x.rpm", "binutils-gold-0:2.41-58.el10_1.2.x86_64.rpm", "binutils-gold-debuginfo-0:2.41-58.el10_1.2.aarch64.rpm", "binutils-gold-debuginfo-0:2.41-58.el10_1.2.ppc64le.rpm", "binutils-gold-debuginfo-0:2.41-58.el10_1.2.s390x.rpm", "binutils-gold-debuginfo-0:2.41-58.el10_1.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 10 updates binutils to fix moderate heap overflow issues. Upgrade needed for system security and stability.. Rocky Linux, binutils, heap overflow, security advisory, software update. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2025 Rocky Linux
217

Oracle: Moderate Memory Access Vulnerability in binutils ELSA-2025-23382

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2025-23382 http://linux.oracle.com/errata/ELSA-2025-23382.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: binutils-2.30-128.0.1.el8_10.x86_64.rpm binutils-devel-2.30-128.0.1.el8_10.i686.rpm binutils-devel-2.30-128.0.1.el8_10.x86_64.rpm aarch64: binutils-2.30-128.0.1.el8_10.aarch64.rpm binutils-devel-2.30-128.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/binutils-2.30-128.0.1.el8_10.src.rpm Related CVEs: CVE-2025-11083 Description of changes: [2.30-128.0.1] - Forward port Oracle patches to 2.30-128 - CVE-2025-11083 Reviewed-by: TBD Oracle history: October-8-2025 Bruce McCulloch - 2.30-127.0.1 - Forward port Oracle patches to 2.30-127. - Muting some failing ld-ctf tests. Reviewed-by: Jose E. Marchesi November-14-2024 Bruce McCulloch - 2.30-125.0.1 - Forward port Oracle patches from 2.30-125 Reviewed-by: Jose E. Marchesi February-06-2024 Nick Alcock - 2.30-123.0.2 - Refresh CTF patches from upstream (2.42). - Fix more cases where operations on child dicts could leave errors on the parent, this time associated with CTF dict creation (upstream PR libctf/30985). - Fix the cu-mapped link feature (not exposed by GNU ld) to use only the last mapping provided for a given translation unit, rather than a random mix of first and last - Fix dependencies of libctf.so and libctf-nobfd.so to cite the libraries the code actually depends on. (Fixes observed link problems with libctf-nobfd.so needing extra libraries on the link line versus upstream: libctf.so changes done purely for consistency.) October-10-2023 Jose E. Marchesi - 2.30-123.0.1 - Forward-port Oracle patches to 2.30-123. Reviewed-by: David Faust August-02-2023 Nick Alcock - 2.30-119.0.2 - Refresh CTF patches from upstream. - Avoid spuriouscorruption error with symtypetab section emitted by old OL8 GCCs - Various obscure install-time linking problems - Make objdump/readelf --ctf parameter optional; make objdump --ctf-parent take a CTF member name, not a section name - Improve dumping of types when some types elicit a libctf error - Put functions as well as variables in the (misnamed) CTF variable section - Improve handling of various forms of corrupted CTF input. - Fix errors in comments in and - Make CTF dicts reproducible even when conflicting types are seen - Prevent corruption of output when linking multiple object files derived from the same source - Minor compiler warning and portability fixes - Fix (unlikely) crash-inducing uninitialized memory access and wild pointer overwrite when linking - Fix the reported offsets of fields within unnamed structs/unions [Orabug: 35191322] - Fix a number of places where operations carried out on child dicts that errored were producing errors on the parent, not the child, so the caller never noticed them March-28-2023 Guillermo E. Martinez - 2.30-119.0.1 - Forward-port Oracle patches from 2.30-117.0.3 to 2.30-119.0.1 - Remove Oracle patch: binutils-bfd-plugin-lib64.patch - Reviewed-by: Jose E. Marchesi October-20-2022 Guillermo E. Martinez - 2.30-117.0.3 - Backport of upstream patches: - [binutils-gdb] Add an option to objcopy to change the alignment of sections. fa463e9fc644e7a3bad39aa73bf6be72ea865805. - [binutils-gdb] Change objcopy's --set-section-alignment option to take a byte alignment value rather than a power of two alignment value. de4859eacb74a440d9fd61e4a0f051e3737a05dd - [Orabug: 34721268] - Reviewed-by: Jose E. Marchesi October-06-2022 Guillermo E. Martinez - 2.30-117.0.2 - Add missed Oracle patches: - binutils-aarch64-veneers-fix.patch. - binutils-aarch64-add-support-efi.patch. - Reviewed-by: Jose E. Marchesi September-28-2022Guillermo E. Martinez - 2.30-117.0.1 - Forward-port of Oracle patches from 2.30-113.0.3 - Reviewed-by: Jose E. Marchesi August-04-2022 Guillermo E. Martinez - 2.30-113.0.3 - Backport of upstream patches: - [binutils-gdb][AArch64] Re: Add support for AArch64 EFI (efi-*-aarch64) d91c67e8730354c43fae86fa98fe593925882365. - [binutils-gdb][AArch64] Re: AArch64: Add support for AArch64 EFI (efi-*-aarch64) 32384aa396e7e87fe02cc838722b8e80ec88ec10. - [binutils-gdb][AArch64] AArch64: Add support for AArch64 EFI (efi-*-aarch64). b69c9d41e89498442cb5af5287f378b3583dd445. - [Orabug: 34453890] - Reviewed-by: Jose E. Marchesi - Reviewed-by: David Faust July-14-2022 Jose E. Marchesi - 2.30-113.0.2 - Backport of upstream patch: [binutils-gdb][ld][AArch64] Fix group_sections algorithm cff69cf4cf97e1eb4c2cca8e985e403b1a97c059. - [Orabug: 34237729] - Reviewed-by: Indu Bhagat March-29-2022 Diego de Dios - 2.30-113.0.1 - Forward-port Oracle patches from 2.30-108.0.2.1 to 2.30-113.0.1 - Reviewed-by: Jose E. Marchesi November-16-2021 David Faust - 2.30-108.0.2.1 - Forward-port Oracle patches from 2.30-108.0.2 to 2.30-108.0.2.1 - Reviewed-by: Jose E. Marchesi November-02-2021 David Faust - 2.30-108.0.2 - Forward-port the following update: [2.30-93.0.4 - Backport fix for fencepost bug in CTF pptrtab usage causing coredumps - Backport test result fixes for new GCC-based CTF generation [Orabug: 33344570] - Reviewed-by: David Faust - Reviewed-by: Jose E. Marchesi October-05-2021 David Faust - 2.30-108.0.1 - Forward-port Oracle patches from 2.30-93.0.3 to 2.30-108.0.1 - Reviewed-by: Elena Zannoni August-17-2021 David Faust - 2.30-93.0.3 - Fix BFD library incorrectly attempting to load 32-bit plugins on OL8. - [Orabug: 33219039] June-16-2021 Nick Alcock - 2.30.93.0.2 - Backport the fully-functional CTF deduplicator. The spurious conflicts in the previous version are gone;ambiguously-defined types and those depending on them are properly shuffled into per-CU dicts; the share-duplicated link mode used by ctfarchive where types only used in one CU end up in a per-CU dict is fully implemented. This is the version that is upstream. The linker is much faster, uses much less memory, and generates much smaller CTF output (usually better than dwarf2ctf despite emitting function types where dwarf2ctf did not) and is much more robust and more heavily tested. - Remove the nondeduplicating CTF linker, and dead code supporting impossible things unnamed typedefs and basic types - Backport the new ld-ctf and libctf testsuites - New linker options --ctf-variables (off by default), --ctf-share-types - func info / data object support (needs compiler changes for working func info support, but all the code is there in binutils now); new API functions to add symbols to a dict, look them up, and iterate over them: ctf_symbol_next, ctf_add_objt_sym, ctf_add_func_sym, ctf_link_add_linker_symbol, ctf_arc_lookup_symbol, ctf_lookup_by_symbol_name, ctf_arc_lookup_symbol_name - Backport numerous bugfixes: fix handling of function types' arglists, allow ctf_type_reference of dynamic slices; prevent some causes of munmap()s of random chunks of memory; improved handling of corrupted dicts; improve dump output some more; fix some error handling bugs; fix opening CTF in binaries with a strtab but no symtab; use a more reliable method to ensure the output has exactly one .ctf section; use the dynamic sections for strings and symbols so that CTF is not corrupted by strip(1); improve the CTF dumper; support unnamed structure members better; fix a theoretical buffer overrun when looking up symbols by name; improve pointer lookup by name in dicts with parents; don't lose types or corrupt the dict when looking up or adding more types in writable dicts after serializing the dict - more armoring againstinvalid CTF and prevention of wrong results when asking for things like the size of opaque forwards or the encoding of enums - gettextization - New public API also used by the deduplicator: improved error reporting and assertion failures; improved _next iterators with most _iter iterators reimplemented using them, new API functions *_next, ctf_type_name_raw, ctf_type_kind_forwarded, ctf_ref, ctf_member_count, ctf_archive_count, ctf_arc_flush_caches, ctf_getsymsect, ctf_getstrsect, ctf_symsect_endianness, ctf_arc_symsect_endianness, ctf_add_unknown; add ctf_dict_t as a recommended new typename for the deprecated ctf_file_t, and new functions with _dict in the name; add the ability to filter out variables from the link - New internal infrastructure: new internal dynhash functions and a new dynset type; higher-efficiency dynhashes; removal of unnecessary duplication in type lookup paths; add optional lazy loading of CTF > at link time (not used by ld); make cu-mapping links (as used by ctfarchive) take much less memory - Run make check in libctf too. - Reviewed-by: David Faust May-18-2021 David Faust - 2.30-93.0.1 - Forward-port Oracle patches from 2.30-90.0.1 - Reviewed-by: Elena Zannoni April-02-2021 David Faust - 2.30-90.0.1 - Forward-port Oracle patches from 2.30-79.0.1 - Reviewed-by: Jose E. Marchesi November-03-2020 David Faust - 2.30-79.0.1 - Forward-port Oracle patches from 2.30-75.0.1 - Reviewed-by: Jose E. Marchesi July-29-2020 David Faust - 2.30-75.0.1 - Forward-port Oracle patches to OL8.3 beta. April-28-2020 Jose E. Marchesi - 2.30-73.0.1 - Forward-port of Oracle patches from 2.30-68.0.2. - Reviewed-by: Elena Zannoni March-17-2020 Nick Alcock - 2.30-68.0.2 - Backport the non-cycle-detecting-capable deduplicating CTF linker - Backport a fix for an upstream hashtab crash (no upstream bug number), triggered by the above. - Fix deduplication of ambiguously-named types in CTF. - CTFtypes without names are not ambiguously-named. - Stop the CTF_LINK_EMPTY_CU_MAPPINGS flag crashing. - Only emit ambiguous types as hidden if they are named and there is already a type with that name. - Make sure completely empty dicts get their header written out properly - Do not fail if adding anonymous struct/union members to structs/unions that already contain other anonymous members at a different offset - Correctly look up pointers to non-root-visible structures - Emit error messages in dumping into the dump stream - Do not abort early on dump-time errors - Elide likely duplicates (same name, same kind) within a single TU (cross- TU duplicate/ambiguous-type detection works as before). - Fix linking of the CTF variable section - Fix spurious conflicts of variables (also affects the nondeduplicating linker) - Defend against CUs without names - When linking only a single input file, set the output CTF CU name to the name of the input - Support cv-qualified bitfields - Fix off-by-one error in SHA-1 sizing January-24-2020 Egeyar Bagcioglu - 2.30-68.0.1 - Ensure 8-byte alignment for AArch64 stubs. - Add CTF support to OL8: CTF machinery, including libctf.so and libctf-nonbfd.so. The linker does not yet deduplicate the CTF type section. - Backport of fix for upstream bug 23919, required by above - [Orabug: 30102938] [Orabug: 30102941] [2.30-128] - Fix a potential illegal memory access when linking a corrupt input file. (RHEL-126878) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated binutils in Oracle Linux 8 addresses a moderate security risk due to potential memory access issues.. Oracle Linux security, memory access issue, binutils update. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2025 Oracle
219

Rocky Linux 9: RLSA-2025:23343 binutils Moderate Buffer Overflow

Moderate: binutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23343", "synopsis": "Moderate: binutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for binutils.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2399948", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948", "description": ""}], "cves": [{"name": "CVE-2025-11083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11083", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-122"}], "references": [], "publishedAt": "2025-12-19T09:05:01.645210Z", "rpms": {"Rocky Linux 9": {"nvras": ["binutils-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-0:2.35.2-67.el9_7.1.i686.rpm", "binutils-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-0:2.35.2-67.el9_7.1.src.rpm", "binutils-0:2.35.2-67.el9_7.1.x86_64.rpm", "binutils-debuginfo-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-debuginfo-0:2.35.2-67.el9_7.1.i686.rpm", "binutils-debuginfo-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-debuginfo-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-debuginfo-0:2.35.2-67.el9_7.1.x86_64.rpm","binutils-debugsource-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-debugsource-0:2.35.2-67.el9_7.1.i686.rpm", "binutils-debugsource-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-debugsource-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-debugsource-0:2.35.2-67.el9_7.1.x86_64.rpm", "binutils-devel-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-devel-0:2.35.2-67.el9_7.1.i686.rpm", "binutils-devel-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-devel-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-devel-0:2.35.2-67.el9_7.1.x86_64.rpm", "binutils-gold-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-gold-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-gold-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-gold-0:2.35.2-67.el9_7.1.x86_64.rpm", "binutils-gold-debuginfo-0:2.35.2-67.el9_7.1.aarch64.rpm", "binutils-gold-debuginfo-0:2.35.2-67.el9_7.1.ppc64le.rpm", "binutils-gold-debuginfo-0:2.35.2-67.el9_7.1.s390x.rpm", "binutils-gold-debuginfo-0:2.35.2-67.el9_7.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical security update for binutils on Rocky Linux 9 addresses a buffer overflow issue ranked moderate severity. Rocky Linux 9, binutils update, moderate severity, heap overflow. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2025 Rocky Linux
219

Rocky Linux 9: RLSA-2025:23336 gcc-toolset-13-binutils Heap Overflow Risk

Moderate: gcc-toolset-13-binutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23336", "synopsis": "Moderate: gcc-toolset-13-binutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for gcc-toolset-13-binutils.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying call graph profile data), ld (the GNU linker), nm (for listing symbols from object files), objcopy (for copying and translating object files), objdump (for displaying information from object files), ranlib (for generating an index for the contents of an archive), readelf (for displaying detailed information about binary files), size (for listing the section sizes of an object or archive file), strings (for listing printable strings from files), strip (for discarding symbols), and addr2line (for converting addresses to file and line).\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2399948", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948", "description": ""}], "cves": [{"name": "CVE-2025-11083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11083", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-122"}], "references": [], "publishedAt": "2025-12-19T09:05:01.645210Z", "rpms": {"Rocky Linux 9": {"nvras":["gcc-toolset-13-binutils-0:2.40-21.el9_7.1.aarch64.rpm", "gcc-toolset-13-binutils-0:2.40-21.el9_7.1.ppc64le.rpm", "gcc-toolset-13-binutils-0:2.40-21.el9_7.1.s390x.rpm", "gcc-toolset-13-binutils-0:2.40-21.el9_7.1.src.rpm", "gcc-toolset-13-binutils-0:2.40-21.el9_7.1.x86_64.rpm", "gcc-toolset-13-binutils-debuginfo-0:2.40-21.el9_7.1.aarch64.rpm", "gcc-toolset-13-binutils-debuginfo-0:2.40-21.el9_7.1.ppc64le.rpm", "gcc-toolset-13-binutils-debuginfo-0:2.40-21.el9_7.1.s390x.rpm", "gcc-toolset-13-binutils-debuginfo-0:2.40-21.el9_7.1.x86_64.rpm", "gcc-toolset-13-binutils-devel-0:2.40-21.el9_7.1.aarch64.rpm", "gcc-toolset-13-binutils-devel-0:2.40-21.el9_7.1.i686.rpm", "gcc-toolset-13-binutils-devel-0:2.40-21.el9_7.1.ppc64le.rpm", "gcc-toolset-13-binutils-devel-0:2.40-21.el9_7.1.s390x.rpm", "gcc-toolset-13-binutils-devel-0:2.40-21.el9_7.1.x86_64.rpm", "gcc-toolset-13-binutils-gold-0:2.40-21.el9_7.1.aarch64.rpm", "gcc-toolset-13-binutils-gold-0:2.40-21.el9_7.1.ppc64le.rpm", "gcc-toolset-13-binutils-gold-0:2.40-21.el9_7.1.s390x.rpm", "gcc-toolset-13-binutils-gold-0:2.40-21.el9_7.1.x86_64.rpm", "gcc-toolset-13-binutils-gold-debuginfo-0:2.40-21.el9_7.1.aarch64.rpm", "gcc-toolset-13-binutils-gold-debuginfo-0:2.40-21.el9_7.1.ppc64le.rpm", "gcc-toolset-13-binutils-gold-debuginfo-0:2.40-21.el9_7.1.s390x.rpm", "gcc-toolset-13-binutils-gold-debuginfo-0:2.40-21.el9_7.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate update for gcc-toolset-13-binutils addresses a heap overflow issue, ensuring system security on Rocky Linux.. gcc-toolset-13-binutils update, Rocky Linux security, binutils heap overflow. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2025 Rocky Linux
219

Rocky Linux 8: RLSA-2025:23382 Binutils Moderate Heap Overflow

Moderate: binutils security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23382", "synopsis": "Moderate: binutils security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for binutils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2399948", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948", "description": ""}], "cves": [{"name": "CVE-2025-11083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-11083", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-122"}], "references": [], "publishedAt": "2025-12-19T09:02:54.260652Z", "rpms": {"Rocky Linux 8": {"nvras": ["binutils-0:2.30-128.el8_10.aarch64.rpm", "binutils-0:2.30-128.el8_10.src.rpm", "binutils-0:2.30-128.el8_10.x86_64.rpm", "binutils-debuginfo-0:2.30-128.el8_10.aarch64.rpm", "binutils-debuginfo-0:2.30-128.el8_10.x86_64.rpm", "binutils-debugsource-0:2.30-128.el8_10.aarch64.rpm", "binutils-debugsource-0:2.30-128.el8_10.i686.rpm", "binutils-debugsource-0:2.30-128.el8_10.x86_64.rpm", "binutils-devel-0:2.30-128.el8_10.aarch64.rpm", "binutils-devel-0:2.30-128.el8_10.i686.rpm", "binutils-devel-0:2.30-128.el8_10.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Security update for Rocky Linux 8 fixes a moderate heap overflow in binutils, enhancing overall system integrity and security.. binutils update, Rocky Linux security, moderate risk, heap overflow fix. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2025 Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200