Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23336 - Security Advisory
Issued:
2025-12-16
Updated:
2025-12-18

RHSA-2025:23336 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: gcc-toolset-13-binutils security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gcc-toolset-13-binutils is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying call graph profile data), ld (the GNU linker), nm (for listing symbols from object files), objcopy (for copying and translating object files), objdump (for displaying information from object files), ranlib (for generating an index for the contents of an archive), readelf (for displaying detailed information about binary files), size (for listing the section sizes of an object or archive file), strings (for listing printable strings from files), strip (for discarding symbols), and addr2line (for converting addresses to file and line).

Security Fix(es):

  • binutils: GNU Binutils Linker heap-based overflow (CVE-2025-11083)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2399948 - CVE-2025-11083 binutils: GNU Binutils Linker heap-based overflow

CVEs

  • CVE-2025-11083

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
gcc-toolset-13-binutils-2.40-21.el9_7.1.src.rpm SHA-256: f33175942a5731c412a8b8243ae46c03f7e10e291ed0d4aaa5f7c832bf440170
x86_64
gcc-toolset-13-binutils-2.40-21.el9_7.1.x86_64.rpm SHA-256: 78a34250881287be979998860aa76b7881f7e5f8be0d52c0583202e2191e4797
gcc-toolset-13-binutils-debuginfo-2.40-21.el9_7.1.i686.rpm SHA-256: 5d9683099d643a7ce0dafb155cf29d4d6c850cf7ef1c816c9c545b8e774d97ba
gcc-toolset-13-binutils-debuginfo-2.40-21.el9_7.1.x86_64.rpm SHA-256: 6f76d7054d3fb75534bc7791d761b8e82dcda92a1c1e72206d97902913759a17
gcc-toolset-13-binutils-devel-2.40-21.el9_7.1.i686.rpm SHA-256: 9b8e151c33adba4baad0c4de410731d6af4c6f57da82ed5ed8d216bfef1ddb18
gcc-toolset-13-binutils-devel-2.40-21.el9_7.1.x86_64.rpm SHA-256: 0607ecd445d5e0250f73f52f826e2186679d2237c59238aff0216e129e85bdc5
gcc-toolset-13-binutils-gold-2.40-21.el9_7.1.x86_64.rpm SHA-256: d8d1afc5139b47c2a93143fd0c73c78281d92fd427c985837ab9fb2b7ca72a7e
gcc-toolset-13-binutils-gold-debuginfo-2.40-21.el9_7.1.i686.rpm SHA-256: b4555bb5bf273bd720b393925267e62261344a64a2cfc45006d0b6dd0072bca6
gcc-toolset-13-binutils-gold-debuginfo-2.40-21.el9_7.1.x86_64.rpm SHA-256: 90caa7a1d46e10f7cef131032396a076e626c9754f91a93ceb55361851741db4
gcc-toolset-13-binutils-gprofng-debuginfo-2.40-21.el9_7.1.x86_64.rpm SHA-256: 32280262a1a4218be77e6d937979dbbfcf48b444bef03e70dc60fbe65d9f744b

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
gcc-toolset-13-binutils-2.40-21.el9_7.1.src.rpm SHA-256: f33175942a5731c412a8b8243ae46c03f7e10e291ed0d4aaa5f7c832bf440170
s390x
gcc-toolset-13-binutils-2.40-21.el9_7.1.s390x.rpm SHA-256: 7b2f71e1bba9e3a67fe6205865f437be812fac93ade2a2038257e5a9d6c89be2
gcc-toolset-13-binutils-debuginfo-2.40-21.el9_7.1.s390x.rpm SHA-256: 9afc4719b377f26a7770f068a327caea2549c3b3088fa56371ff2a8ae2fad30f
gcc-toolset-13-binutils-devel-2.40-21.el9_7.1.s390x.rpm SHA-256: b6d2cbd3f8ff06c647ea71e44e1cf407df43ff5f0b72c9d0c38db9595b871402
gcc-toolset-13-binutils-gold-2.40-21.el9_7.1.s390x.rpm SHA-256: 5554b66fe5ad3b780a096f8847bf07b03bc232f003a32baebded8c68a2280383
gcc-toolset-13-binutils-gold-debuginfo-2.40-21.el9_7.1.s390x.rpm SHA-256: f584f653c281bfabdf652ea8b8569fdab572adc73f7fa749939f9389fd8d5451

Red Hat Enterprise Linux for Power, little endian 9

SRPM
gcc-toolset-13-binutils-2.40-21.el9_7.1.src.rpm SHA-256: f33175942a5731c412a8b8243ae46c03f7e10e291ed0d4aaa5f7c832bf440170
ppc64le
gcc-toolset-13-binutils-2.40-21.el9_7.1.ppc64le.rpm SHA-256: eed37d5ab90659772eac53642692b711e0f317b2056cb4b47549f30ca61d23ae
gcc-toolset-13-binutils-debuginfo-2.40-21.el9_7.1.ppc64le.rpm SHA-256: 9c8a04a6553895b55c07c363bd8230b32f884d85aa8596ef0f461b0a220e853e
gcc-toolset-13-binutils-devel-2.40-21.el9_7.1.ppc64le.rpm SHA-256: a76c6a57803ec73b9c3b67c5dea888f78e5afecd66cd32a62222231a5d646d47
gcc-toolset-13-binutils-gold-2.40-21.el9_7.1.ppc64le.rpm SHA-256: dd11adf3eeb4f16f700d9474d748790c7bb38cacecc108b48dc061d3fd83c3dd
gcc-toolset-13-binutils-gold-debuginfo-2.40-21.el9_7.1.ppc64le.rpm SHA-256: 5a31e3ed46085355627c051712208d0a833d31446c4d46ccd03352111b139c9f

Red Hat Enterprise Linux for ARM 64 9

SRPM
gcc-toolset-13-binutils-2.40-21.el9_7.1.src.rpm SHA-256: f33175942a5731c412a8b8243ae46c03f7e10e291ed0d4aaa5f7c832bf440170
aarch64
gcc-toolset-13-binutils-2.40-21.el9_7.1.aarch64.rpm SHA-256: 6344c3184cd3650559d99886133b9c4e158e063905f418710d5abb6b200d6936
gcc-toolset-13-binutils-debuginfo-2.40-21.el9_7.1.aarch64.rpm SHA-256: 6d99727aee6ef30814d5dd2b3e608cd8cf7b74e4bda09c981f9cfcf5ab445cd8
gcc-toolset-13-binutils-devel-2.40-21.el9_7.1.aarch64.rpm SHA-256: 7b8e8ad41525b558807a0e9ee6b03a48d2dde70baaf0b3c627fb1ad462e7f13d
gcc-toolset-13-binutils-gold-2.40-21.el9_7.1.aarch64.rpm SHA-256: 3f8f59b96eb6e6482921ee8d866193c4d17b5871a7d90c88396225f64690a119
gcc-toolset-13-binutils-gold-debuginfo-2.40-21.el9_7.1.aarch64.rpm SHA-256: 33b5f813238fbfc1aa26fcfd8cba0c0d98178681e36d9e5807f17c7a3510cd1c
gcc-toolset-13-binutils-gprofng-debuginfo-2.40-21.el9_7.1.aarch64.rpm SHA-256: a5032fae13644ef1940a31dd1ed90d8d34ce9447c0645ebfcb06ad74f0ff563f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility