RHSA-2026:7098MediumCVSS 5.3

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 8, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (25)

📋 Description

CVE-2025-11081 — binutils: GNU Binutils out-of-bounds read CVE-2025-11082 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11083 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11412 — binutils: GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds CVE-2025-11413 — binutils: GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds CVE-2025-11414 — binutils: GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds CVE-2025-11494 — binutils: GNU Binutils Linker out-of-bounds read CVE-2025-11495 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11839 — binutils: GNU Binutils prdbg.c tg_tag_type return value CVE-2025-11840 — binutils: GNU Binutils out-of-bounds read CVE-2025-66861 — binutils: out-of-bounds read in d_unqualified_name() in cp-demangle.c CVE-2025-66862 — binutils: heap-based buffer over-read in gnu_special() in cplus-dem.c CVE-2025-66863 — binutils: BinUtils: Denial of Service via crafted PE file CVE-2025-66864 — binutils: NULL pointer dereference in d_print_comp_inner() in cp-demangle.c CVE-2025-66865 — binutils: stack overflow in d_print_comp_inner() in cp-demangle.c CVE-2025-66866 — binutils: BinUtils: Denial of Service via crafted PE file CVE-2025-69644 — binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information CVE-2025-69645 — binutils: Binutils objdump: Denial of Service via crafted DWARF debug information CVE-2025-69646 — binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data CVE-2025-69647 — binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data CVE-2025-69648 — binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data CVE-2025-69649 — binutils: NULL pointer dereference in readelf via crafted ELF binary with malformed header fields CVE-2025-69650 — binutils: double free in readelf via crafted ELF binary with malformed relocation data CVE-2025-69651 — binutils: Binutils: Denial of Service via crafted ELF binary processing CVE-2025-69652 — binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

🎯 Affected products4

  • Red Hat Hardened Images
  • binutils-main@aarch64 as a component of Red Hat Hardened Images
  • binutils-main@src as a component of Red Hat Hardened Images
  • binutils-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To reduce the risk of exploitation, users should avoid processing Portable Executable (PE) files from untrusted or unverified sources with BinUtils tools. Limiting the exposure of BinUtils to untrusted input can help prevent denial of service attacks. Workaround: To mitigate this issue, users should avoid processing untrusted Portable Executable (PE) files with applications linked against BinUtils. Restricting the source of PE files to trusted origins can reduce the attack surface. Workaround: To mitigate this vulnerability, do not process untrusted, unverified or externally supplied ELF binaries with the readelf program.

🔗 References (29)