Patch Status for CVE-2025-11083

Maganuru Jayasurya Maganuru.Jayasurya@windriver.com
Mon Oct 13 13:51:39 GMT 2025


Dear Binutils Team,

CVE-2025-11083, associated with Bugzilla bug 33457 (heap-buffer-overflow 
in |cache_bwrite| at |cache.c:435|), affects the |binutils_2_45| branch.

This is being addressed as part of ongoing work on the Yocto Project 
(Poky), with the goal of applying all necessary patches to ensure the 
CVE is fully resolved.

Findings so far:

  *

    Bug 33457 includes a patch and is marked RESOLVED FIXED. The heap
    overflow no longer occurs after applying this patch.

  *

    Bug 33456 appears to cover both 33456 and 33457 with a single patch.

  *

    Multiple related bugs (e.g., 33449, 33450, 33451, 33452, 33456,
    33458, 33465, 33466, 33471) are marked as duplicates and resolved;
    some required individual patches.

  *

    Bug 33453 is marked as a duplicate of 33457, but its status remains
    UNCONFIRMED.

Requesting confirmation:
Which patches are required to fully address CVE-2025-11083 on the 
|binutils_2_45| branch?

Regards,
Jayasurya

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://sourceware.org/pipermail/binutils/attachments/20251013/bd10d5b3/attachment-0001.htm>


More information about the Binutils mailing list