[Git][security-tracker-team/security-tracker][master] Update status for some binutils issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 07:08:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
356282f9 by Salvatore Bonaccorso at 2026-07-28T08:06:40+02:00
Update status for some binutils issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -71589,10 +71589,10 @@ CVE-2026-6855 (A flaw was found in InstructLab. A local attacker could exploit a
 CVE-2026-6848 (A flaw was found in Red Hat Quay. When Red Hat Quay requests password  ...)
 	NOT-FOR-US: Red Hat Quay
 CVE-2026-6846 (A flaw was found in binutils. A heap-buffer-overflow vulnerability exi ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.47-1 (unimportant)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460006
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34049
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7a089e0302382f4d4e077941156e1eaa68d01393
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7a089e0302382f4d4e077941156e1eaa68d01393 (binutils-2_47)
 	NOTE: binutils not covered by security support
 CVE-2026-6845 (A flaw was found in binutils, specifically within the `readelf` utilit ...)
 	- binutils <unfixed> (unimportant)
@@ -89804,9 +89804,9 @@ CVE-2026-4673 (Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.
 	- chromium 146.0.7680.164-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-4647 (A flaw was found in the GNU Binutils BFD library, a widely used compon ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.47-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33919
-	NOTE: Fixed by: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9e99dbc1f19ffaf18d0250788951706066ebe7f2
+	NOTE: Fixed by: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9e99dbc1f19ffaf18d0250788951706066ebe7f2 (binutils-2_47)
 	NOTE: binutils not covered by security support
 CVE-2026-4645
 	REJECTED
@@ -96897,14 +96897,14 @@ CVE-2025-70031 (An issue pertaining to CWE-352: Cross-Site Request Forgery was d
 CVE-2025-70030 (An issue pertaining to CWE-1333: Inefficient Regular Expression Comple ...)
 	NOT-FOR-US: Sunbird-Ed SunbirdEd-portal
 CVE-2025-69648 (GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerab ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33641
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69647 (GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerab ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33640
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69279 (In nr modem, there is a possible system crash due to improper input va ...)
 	NOT-FOR-US: Unisoc
@@ -97633,39 +97633,39 @@ CVE-2025-69653 (A crafted JavaScript input can trigger an internal assertion fai
 	NOTE: https://github.com/bellard/quickjs/issues/467
 	NOTE: Fixed by: https://github.com/bellard/quickjs/commit/1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6
 CVE-2025-69652 (GNU Binutils thru 2.46 readelf contains a vulnerability that leads to  ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33701
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69651 (GNU Binutils thru 2.46 readelf contains a vulnerability that leads to  ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33700
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69650 (GNU Binutils thru 2.46 readelf contains a double free vulnerability wh ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33698
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69649 (GNU Binutils thru 2.46 readelf contains a null pointer dereference vul ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33697
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69646 (Binutils objdump contains a denial-of-service vulnerability when proce ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33638
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69645 (Binutils objdump contains a denial-of-service vulnerability when proce ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33637
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-69644 (An issue was discovered in Binutils before 2.46. The objdump contains  ...)
-	- binutils <unfixed> (unimportant)
+	- binutils 2.46-1 (unimportant)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33639
-	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7
+	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7 (binutils-2_46)
 	NOTE: binutils not covered by security support
 CVE-2025-15602 (Snipe-IT versions prior to 8.3.7 contain sensitive user attributes rel ...)
 	- snipe-it <itp> (bug #1005172)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/356282f9e4152b3abf132883db50431879ebebd4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/356282f9e4152b3abf132883db50431879ebebd4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/42433bfd/attachment.htm>


More information about the debian-security-tracker-commits mailing list