ELSA-2025-20155-0

ELSA-2025-20155-0 - binutils security update

Type:SECURITY
Impact:MODERATE
Release Date:2025-11-25

Description


[2.41-58.0.1]
- Forward-port Oracle patches to 2.41-58.
- Reviewed-by: Jose E. Marchesi
Oracle history:
August-29-2025 Bruce McCulloch - 2.41-57.0.1
- Forward-port Oracle patches to 2.41-57.
Reviewed-by: Jose E. Marchesi
Jun-04-2025 Bruce McCulloch - 2.41-53.0.3
- Add binutils-orabug-38018827.patch.
- Fix ctf_dict_open clobbering errno.
- Backport of upstream commit:
- 14303d6295e libctf: archive, open: when opening, always set errp to
something.
- [Orabug: 38018827]
- Add binutils-orabug-38018828.patch.
- In kernel links, properly hide CTF types only if conflicting.
- Backport of upstream commits:
- 75e514cfa56 Revert 'libctf: fix linking of non-root-visible types'
- 002957be18e libctf: dedup: improve hiding of conflicting types in the
same dict
- [Orabug: 38018828]
Reviewed-by: Jose E. Marchesi
Reviewed-by: Nick Alcock
Reviewed-by: Elena Zannoni
May-28-2025 Vladimir Mezentsev - 2.41-53.0.2
- Backported updates for gprofng.
Reviewed-by: Bruce McCulloch
April-02-2025 Bruce McCulloch - 2.41-53.0.1
- Merge Oracle patches to 2.41-53.
Reviewed-by: Jose E. Marchesi
November-28-2024 Nick Alcock - 2.41-45.0.1
- Latest CTF changes from upstream
- add ctf_dict_set_flag, ctf_lookup_enumerator, ctf_lookup_enumerator_next,
ctf_arc_lookup_enumerator_next; consider enums with differing enumerators
to be conflicting
- add documentation to ctf-api.h
- allow modification of ctf_opened dicts and opening of foreign-
endian older dicts
- looking up types by name prefers non-bitfields if possible
- bugfixes to parent propagation, rewriting of existing dicts,
ctf_archive_count, CU-mapped links, and dumping and linking of
non-root-visible types.
- fix a bunch of small leaks and one big one (on ctf_open error)
- fix a write into freed memory after ctf_rollback and writeout
- internal improvements to serialization, name lookup, symbol
lookup, string handling, and more
- explicitly disable zstd support (enabling requires addition of zstd to
the .so scripts)

[2.41-58]
- Remove workaround for CVE-2025-5702. (RHEL-100159)

[2.41-57]
- Add fix for CVE-2025-5244. (RHEL-100417)
- USe correct fix for CVE-2025-5702. (RHEL-100159)

[2.41-56]
- Add basic support for RISC-V 64-bit EFI objects. (RHEL-88815)

[2.41-55]
- Adds z17 as a cpu name for the s390x architecture. (RHEL-87215)

[2.41-54]
- Fix BuildRequires for non-gold architectures. (RHEL-85855)
- Fix RISC-V ld testsuite failures (thanks Nick Clifton). (RHEL-85855)


Related CVEs


CVE-2025-5244

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_aarch64_addons
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_aarch64_appstream
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_aarch64_baseos_latest
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_aarch64_u1_baseos_base
binutils-2.41-58.0.1.el10.aarch64.rpm314b6b4403d88c09f86baadc0c734fe3f2e65c63f096a141bc4d05f9c04d6720-ol10_aarch64_baseos_latest
binutils-2.41-58.0.1.el10.aarch64.rpm314b6b4403d88c09f86baadc0c734fe3f2e65c63f096a141bc4d05f9c04d6720-ol10_aarch64_u1_baseos_base
binutils-devel-2.41-58.0.1.el10.aarch64.rpma408a6592c132c41b4565485511263e18fa0661fd488f16f245c5ce7b2c78b93-ol10_aarch64_appstream
binutils-gold-2.41-58.0.1.el10.aarch64.rpm3d2263a0dc532575c0285e9bdcfd26a15a02be42f741237fb8ab5926c0b23456-ol10_aarch64_baseos_latest
binutils-gold-2.41-58.0.1.el10.aarch64.rpm3d2263a0dc532575c0285e9bdcfd26a15a02be42f741237fb8ab5926c0b23456-ol10_aarch64_u1_baseos_base
Oracle Linux 10 (x86_64) binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_x86_64_addons
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_x86_64_appstream
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_x86_64_baseos_latest
binutils-2.41-58.0.1.el10.src.rpmbc0689e97e49be366a1065ebaf76fe54cbeeaed1fecba7a65e1e95a58f743c79-ol10_x86_64_u1_baseos_base
binutils-2.41-58.0.1.el10.x86_64.rpmbb0a05fbd0d85e27d494f557f55aafd1f5889dbe263c6a76a9879e43b629dd08-ol10_x86_64_baseos_latest
binutils-2.41-58.0.1.el10.x86_64.rpmbb0a05fbd0d85e27d494f557f55aafd1f5889dbe263c6a76a9879e43b629dd08-ol10_x86_64_u1_baseos_base
binutils-devel-2.41-58.0.1.el10.x86_64.rpmab65ca3c9a5d22ea3c34efd64fa0cafa3e1a3135d1eda04b2c587946c6b82ccc-ol10_x86_64_appstream
binutils-gold-2.41-58.0.1.el10.x86_64.rpm8e092ed8b3920d2235f604c6de2afecda8e1054b83f3ec0587a2372367c97f67-ol10_x86_64_baseos_latest
binutils-gold-2.41-58.0.1.el10.x86_64.rpm8e092ed8b3920d2235f604c6de2afecda8e1054b83f3ec0587a2372367c97f67-ol10_x86_64_u1_baseos_base



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete