{"schema_version": "1.7.0", "id": "RLSA-2025:23306", "modified": "2025-12-20T09:09:00.656046Z", "published": "2025-12-20T09:08:07.642679Z", "upstream": ["CVE-2025-11082", "CVE-2025-11083"], "summary": "Moderate: binutils security update", "details": "The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.\n\nSecurity Fix(es):\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11082)\n\n* binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}], "affected": [{"package": {"ecosystem": "Rocky Linux:10", "name": "binutils", "purl": "pkg:rpm/rocky-linux/binutils?distro=rocky-linux-10&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:2.41-58.el10_1.2"}], "database_specific": {"yum_repository": "BaseOS"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2025:23306"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2399943"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2399948"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}