[CLSA-2026:1777476417] binutils: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-29 15:27:02 UTC
Description:
- CVE-2026-3441: bounds-check XTY_LD x_scnlen csect index in xcoff_link_add_symbols to prevent heap-based out-of-bounds read - CVE-2026-3442: validate r_symndx before sym_hashes[] indexing in xcoff_link_add_symbols to prevent out-of-bounds read
Updated packages:
  • binutils-2.29.1-31.amzn2.0.2.tuxcare.els10.x86_64.rpm
    sha:690f27cda5a9a4f84108b9884707ebe3c963f8195da1610f933f06c33c376f68
  • binutils-devel-2.29.1-31.amzn2.0.2.tuxcare.els10.x86_64.rpm
    sha:beda2bf324495f9bae7f5025cb406ad9b26ea90116edb84b492b0e0a44ed196d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.