<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
<generator>
<oval:product_name>Oracle Errata System</oval:product_name>
<oval:product_version>Oracle Linux</oval:product_version>
<oval:schema_version>5.11</oval:schema_version>
<oval:timestamp>2025-12-19T07:03:03</oval:timestamp>
</generator>
<definitions>
<definition id="oval:com.oracle.elsa:def:202523336" version="501" class="patch">
<metadata>
<title>
ELSA-2025-23336:  gcc-toolset-13-binutils security update (MODERATE)
</title>
<affected family="unix">
<platform>Oracle Linux 9</platform>

</affected>
<reference source="elsa" ref_id="ELSA-2025-23336" ref_url="https://linux.oracle.com/errata/ELSA-2025-23336.html"/>
<reference source="CVE" ref_id="CVE-2025-11083" ref_url="https://linux.oracle.com/cve/CVE-2025-11083.html"/>

<description>
[2.40-21.0.1.1]
- Forward-port Oracle patches to 2.40-21.1.
  - CVE-2025-11083
  - Reviewed-by: David Faust &lt;david.faust@oracle.com&gt;
  Oracle history:
  April-02-2024 Jose E. Marchesi  &lt;jose.marchesi@oracle.com&gt; - 2.40-21.0.1
  - Forward-port Oracle patchs to 2.40-21.
  - Reviewed-by: Cupertino Miranda &lt;cupertino.miranda@oracle.com&gt;
  December-15-2023 Jose E. Marchesi  &lt;jose.marchesi@oracle.com&gt; - 2.40-13.0.1
  - libctf, link: fix CU-mapped links with CTF_LINK_EMPTY_CU_MAPPINGS.
    Backport of upstream commit 869a750c0ec0abcab84e38a43a1ed73321ef4371.
    [Orabug: 36113992]
  - Reviewed-by: David Faust &lt;david.faust@oracle.com&gt;

[2.40-21.1]
- Fix a potential illegal memory access when linking a corrupt input file.  (RHEL-130652)
</description>
<!--
 ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ 
-->
<advisory>
<severity>MODERATE</severity>
<rights>Copyright 2025 Oracle, Inc.</rights>
<issued date="2025-12-18"/>
<cve cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://linux.oracle.com/cve/CVE-2025-11083.html" public="20250927">CVE-2025-11083</cve>

<affected_cpe_list>
<cpe>cpe:/a:oracle:linux:9::appstream</cpe>
</affected_cpe_list>
</advisory>
</metadata>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336001" comment="Oracle Linux 9 is installed"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336002" comment="Oracle Linux arch is aarch64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336003" comment="gcc-toolset-13-binutils is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336004" comment="gcc-toolset-13-binutils is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336005" comment="gcc-toolset-13-binutils-devel is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336006" comment="gcc-toolset-13-binutils-devel is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336007" comment="gcc-toolset-13-binutils-gold is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336008" comment="gcc-toolset-13-binutils-gold is signed with the Oracle Linux 9 key"/>
</criteria>
</criteria>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336009" comment="Oracle Linux arch is x86_64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336003" comment="gcc-toolset-13-binutils is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336004" comment="gcc-toolset-13-binutils is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336005" comment="gcc-toolset-13-binutils-devel is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336006" comment="gcc-toolset-13-binutils-devel is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202523336007" comment="gcc-toolset-13-binutils-gold is earlier than 0:2.40-21.0.1.el9_7.1"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202523336008" comment="gcc-toolset-13-binutils-gold is signed with the Oracle Linux 9 key"/>
</criteria>
</criteria>
</criteria>
</criteria>
</criteria>

</definition>
</definitions>
<!--
 ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<tests>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336001"  version="501" comment="Oracle Linux 9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336001" />
<state state_ref="oval:com.oracle.elsa:ste:202523336002" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336002"  version="501" comment="Oracle Linux arch is aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336001" />
<state state_ref="oval:com.oracle.elsa:ste:202523336003" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336003"  version="501" comment="gcc-toolset-13-binutils is earlier than 0:2.40-21.0.1.el9_7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336002" />
<state state_ref="oval:com.oracle.elsa:ste:202523336004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336004"  version="501" comment="gcc-toolset-13-binutils is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336002" />
<state state_ref="oval:com.oracle.elsa:ste:202523336001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336005"  version="501" comment="gcc-toolset-13-binutils-devel is earlier than 0:2.40-21.0.1.el9_7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336003" />
<state state_ref="oval:com.oracle.elsa:ste:202523336004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336006"  version="501" comment="gcc-toolset-13-binutils-devel is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336003" />
<state state_ref="oval:com.oracle.elsa:ste:202523336001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336007"  version="501" comment="gcc-toolset-13-binutils-gold is earlier than 0:2.40-21.0.1.el9_7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336004" />
<state state_ref="oval:com.oracle.elsa:ste:202523336004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336008"  version="501" comment="gcc-toolset-13-binutils-gold is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336004" />
<state state_ref="oval:com.oracle.elsa:ste:202523336001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202523336009"  version="501" comment="Oracle Linux arch is x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202523336001" />
<state state_ref="oval:com.oracle.elsa:ste:202523336005" />
</rpminfo_test>

</tests>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ 
-->
<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202523336004" version="501">
<name>gcc-toolset-13-binutils-gold</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202523336002" version="501">
<name>gcc-toolset-13-binutils</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202523336003" version="501">
<name>gcc-toolset-13-binutils-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202523336001" version="501">
<name>oraclelinux-release</name>
</rpminfo_object>

</objects>
<states>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202523336001" version="501">
<signature_keyid operation="equals">bc4d06a08d8b756f</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202523336002" version="501">
<version operation="pattern match">^9</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202523336003" version="501">
<arch operation="pattern match">aarch64</arch>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202523336004" version="501">
<evr datatype="evr_string" operation="less than">0:2.40-21.0.1.el9_7.1</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202523336005" version="501">
<arch operation="pattern match">x86_64</arch>
</rpminfo_state>

</states>
</oval_definitions>
