Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:4730 - Security Advisory
Issued:
2021-11-18
Updated:
2021-11-18

RHSA-2021:4730 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: devtoolset-11-binutils security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for devtoolset-11-binutils is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.

Security Fix(es):

  • Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks (CVE-2021-42574)

The following changes were introduced in binutils in order to facilitate detection of BiDi Unicode characters:

Tools which display names or strings (readelf, strings, nm, objdump) have a new command line option --unicode / -U which controls how Unicode characters are handled.

Using "--unicode=default" will treat them as normal for the tool. This is the default behaviour when --unicode option is not used.
Using "--unicode=locale" will display them according to the current locale.
Using "--unicode=hex" will display them as hex byte values.
Using "--unicode=escape" will display them as Unicode escape sequences.
Using "--unicode=highlight" will display them as Unicode escape sequences highlighted in red, if supported by the output device.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7.7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7.7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7.7 ppc64le
  • Red Hat Software Collections (for RHEL Server for IBM Power) 1 for RHEL 7.7 ppc64
  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
  • Red Hat Software Collections (for RHEL Server for IBM Power) 1 for RHEL 7 ppc64
  • Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64

Fixes

  • BZ - 2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks

CVEs

  • CVE-2021-42574

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2021-007
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7.7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
x86_64
devtoolset-11-binutils-2.36.1-1.el7.1.x86_64.rpm SHA-256: fd1291b4d590f92e8c2637359a3d911f138bcc96815f1964680c20a55e78e220
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.i686.rpm SHA-256: 0a8786e1689f196162021659bab87b0b78b3689cab240d79f4caa2bfb93c1008
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.x86_64.rpm SHA-256: 05c98c85f06a0fc95c147e701493537d6f1f5b17a73161ff79d13063966538b6
devtoolset-11-binutils-devel-2.36.1-1.el7.1.i686.rpm SHA-256: bd54ff2bdf780aff9ab445e341afe8e8fde728c12e7decf1cef0ceee42146df1
devtoolset-11-binutils-devel-2.36.1-1.el7.1.x86_64.rpm SHA-256: d4aab33efb69498b4e22447db042cccf925ad80277a31cebc02eedb04ea82004

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7.7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
s390x
devtoolset-11-binutils-2.36.1-1.el7.1.s390x.rpm SHA-256: e0b1fbec244919269a9bedf95d1f16f61dfc5844d2796748b8b122642a573c16
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.s390x.rpm SHA-256: 4422732e841083899953c2261cbdc69f6f7317526937a9015117d6070b12904a
devtoolset-11-binutils-devel-2.36.1-1.el7.1.s390x.rpm SHA-256: 21e8f9b909eeb730eee22e958f5f8757bb552dbe0ba73447835e5c6bb92c93cf

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7.7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
ppc64le
devtoolset-11-binutils-2.36.1-1.el7.1.ppc64le.rpm SHA-256: a9602d6c6c64664039bd53ea719151543fa016c4a84e8322483b8ab9d742a59d
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.ppc64le.rpm SHA-256: f75a417b12de88f57d7354ce678a4e9cd98e820e27c2728319297af5153e8e37
devtoolset-11-binutils-devel-2.36.1-1.el7.1.ppc64le.rpm SHA-256: 23e93dc5af6dadfc611ea891219a10539c86ae460205c3b45eedbb45d61652de

Red Hat Software Collections (for RHEL Server for IBM Power) 1 for RHEL 7.7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
ppc64
devtoolset-11-binutils-2.36.1-1.el7.1.ppc64.rpm SHA-256: 18d63877b130489247c38d27d7309f5fe136258ea3468129424e0e1c59360611
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.ppc64.rpm SHA-256: 925880a8b91aa87c7abc180a1cc537c2efaf9c181fed99084cdbd88d30e8db92
devtoolset-11-binutils-devel-2.36.1-1.el7.1.ppc64.rpm SHA-256: 9bbd555aa28317a9bf1a0cdd800a1b99a13b4796e6dfade01fc007e6a6d96499

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
x86_64
devtoolset-11-binutils-2.36.1-1.el7.1.x86_64.rpm SHA-256: fd1291b4d590f92e8c2637359a3d911f138bcc96815f1964680c20a55e78e220
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.i686.rpm SHA-256: 0a8786e1689f196162021659bab87b0b78b3689cab240d79f4caa2bfb93c1008
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.x86_64.rpm SHA-256: 05c98c85f06a0fc95c147e701493537d6f1f5b17a73161ff79d13063966538b6
devtoolset-11-binutils-devel-2.36.1-1.el7.1.i686.rpm SHA-256: bd54ff2bdf780aff9ab445e341afe8e8fde728c12e7decf1cef0ceee42146df1
devtoolset-11-binutils-devel-2.36.1-1.el7.1.x86_64.rpm SHA-256: d4aab33efb69498b4e22447db042cccf925ad80277a31cebc02eedb04ea82004

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
s390x
devtoolset-11-binutils-2.36.1-1.el7.1.s390x.rpm SHA-256: e0b1fbec244919269a9bedf95d1f16f61dfc5844d2796748b8b122642a573c16
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.s390x.rpm SHA-256: 4422732e841083899953c2261cbdc69f6f7317526937a9015117d6070b12904a
devtoolset-11-binutils-devel-2.36.1-1.el7.1.s390x.rpm SHA-256: 21e8f9b909eeb730eee22e958f5f8757bb552dbe0ba73447835e5c6bb92c93cf

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
ppc64le
devtoolset-11-binutils-2.36.1-1.el7.1.ppc64le.rpm SHA-256: a9602d6c6c64664039bd53ea719151543fa016c4a84e8322483b8ab9d742a59d
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.ppc64le.rpm SHA-256: f75a417b12de88f57d7354ce678a4e9cd98e820e27c2728319297af5153e8e37
devtoolset-11-binutils-devel-2.36.1-1.el7.1.ppc64le.rpm SHA-256: 23e93dc5af6dadfc611ea891219a10539c86ae460205c3b45eedbb45d61652de

Red Hat Software Collections (for RHEL Server for IBM Power) 1 for RHEL 7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
ppc64
devtoolset-11-binutils-2.36.1-1.el7.1.ppc64.rpm SHA-256: 18d63877b130489247c38d27d7309f5fe136258ea3468129424e0e1c59360611
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.ppc64.rpm SHA-256: 925880a8b91aa87c7abc180a1cc537c2efaf9c181fed99084cdbd88d30e8db92
devtoolset-11-binutils-devel-2.36.1-1.el7.1.ppc64.rpm SHA-256: 9bbd555aa28317a9bf1a0cdd800a1b99a13b4796e6dfade01fc007e6a6d96499

Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7

SRPM
devtoolset-11-binutils-2.36.1-1.el7.1.src.rpm SHA-256: b9d01fad362f538f25647355765022080ba49af063c80a2764c33cb12fb1705f
x86_64
devtoolset-11-binutils-2.36.1-1.el7.1.x86_64.rpm SHA-256: fd1291b4d590f92e8c2637359a3d911f138bcc96815f1964680c20a55e78e220
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.i686.rpm SHA-256: 0a8786e1689f196162021659bab87b0b78b3689cab240d79f4caa2bfb93c1008
devtoolset-11-binutils-debuginfo-2.36.1-1.el7.1.x86_64.rpm SHA-256: 05c98c85f06a0fc95c147e701493537d6f1f5b17a73161ff79d13063966538b6
devtoolset-11-binutils-devel-2.36.1-1.el7.1.i686.rpm SHA-256: bd54ff2bdf780aff9ab445e341afe8e8fde728c12e7decf1cef0ceee42146df1
devtoolset-11-binutils-devel-2.36.1-1.el7.1.x86_64.rpm SHA-256: d4aab33efb69498b4e22447db042cccf925ad80277a31cebc02eedb04ea82004

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility