Request for Clarification on Patches Required for CVE-2025-11083
Maganuru Jayasurya
maganuru.jayasurya@blackfigtech.com
Fri Oct 10 11:24:26 GMT 2025
Dear Binutils Team,
We are working on fixing CVE-2025-11083, which relates to Bugzilla bug 33457 ,
(heap-buffer-overflow in cache_bwrite at cache.c:435). The issue is seen in the binutils_2-45-branch.
We are doing this as part of our work on the Yocto Project (Poky) and
want to make sure we apply all necessary patches to ensure the CVE is fully resolved.
Here is what we have found so far:
* Bug 33457 has a patch and is marked RESOLVED FIXED.
After applying the patch, the heap overflow no longer occurs.
* Bug 33456 appears to cover both 33456 and 33457 with a single patch.
* Several related bugs (eg: 33449, 33450, 33451,33452, 33456, 33458, 33465, 33466, 33471)
are marked as duplicates and status as RESOLVED. Few of them require their own patches.
* 33453 is marked as duplicate of 33457 but status is unconfirmed.
Could you please confirm:
Which patches are needed to fully fix CVE-2025-11083?
Regards,
Jayasurya
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://sourceware.org/pipermail/binutils/attachments/20251010/76d87848/attachment.htm>
More information about the Binutils
mailing list