Patch Status for CVE-2025-11083
Maganuru Jayasurya
Maganuru.Jayasurya@windriver.com
Mon Oct 13 13:51:39 GMT 2025
Dear Binutils Team,
CVE-2025-11083, associated with Bugzilla bug 33457 (heap-buffer-overflow
in |cache_bwrite| at |cache.c:435|), affects the |binutils_2_45| branch.
This is being addressed as part of ongoing work on the Yocto Project
(Poky), with the goal of applying all necessary patches to ensure the
CVE is fully resolved.
Findings so far:
*
Bug 33457 includes a patch and is marked RESOLVED FIXED. The heap
overflow no longer occurs after applying this patch.
*
Bug 33456 appears to cover both 33456 and 33457 with a single patch.
*
Multiple related bugs (e.g., 33449, 33450, 33451, 33452, 33456,
33458, 33465, 33466, 33471) are marked as duplicates and resolved;
some required individual patches.
*
Bug 33453 is marked as a duplicate of 33457, but its status remains
UNCONFIRMED.
Requesting confirmation:
Which patches are required to fully address CVE-2025-11083 on the
|binutils_2_45| branch?
Regards,
Jayasurya
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://sourceware.org/pipermail/binutils/attachments/20251013/bd10d5b3/attachment-0001.htm>
More information about the Binutils
mailing list