Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions SPECS/binutils/CVE-2025-3198.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
From 5319826c1d9900d38d8a3c5966ed000ba435e0e1 Mon Sep 17 00:00:00 2001
From: Alan Modra <amodra@gmail.com>
Date: Wed, 19 Feb 2025 07:58:54 +1030
Subject: [PATCH] PR32716, objdump -i memory leak

PR binutils/32716
* bucomm.c (display_info): Free arg.info.

Signed-off-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com>
Upstream-reference: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d;a=patch;
---
binutils-2.41/binutils/bucomm.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/binutils-2.41/binutils/bucomm.c b/binutils-2.41/binutils/bucomm.c
index c268fd3d..b40447c7 100644
--- a/binutils-2.41/binutils/bucomm.c
+++ b/binutils-2.41/binutils/bucomm.c
@@ -435,6 +435,7 @@ display_info (void)
if (!arg.error)
display_target_tables (&arg);

+ free (arg.info);
return arg.error;
}

--
2.45.4

6 changes: 5 additions & 1 deletion SPECS/binutils/binutils.spec
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
Summary: Contains a linker, an assembler, and other tools
Name: binutils
Version: 2.41
Release: 12%{?dist}
Release: 13%{?dist}
License: GPLv2+
Vendor: Microsoft Corporation
Distribution: Azure Linux
Expand Down Expand Up @@ -57,6 +57,7 @@ Patch23: CVE-2025-11839.patch
Patch24: CVE-2025-69647.patch
Patch25: CVE-2026-4647.patch
Patch26: CVE-2026-6846.patch
Patch27: CVE-2025-3198.patch
Provides: bundled(libiberty)

# Moving macro before the "SourceX" tags breaks PR checks parsing the specs.
Expand Down Expand Up @@ -346,6 +347,9 @@ find %{buildroot} -type f -name "*.la" -delete -print
%do_files aarch64-linux-gnu %{build_aarch64}

%changelog
* Tue May 19 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 2.41-13
- Patch for CVE-2025-3198

* Mon May 04 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 2.41-12
- Patch for CVE-2026-6846

Expand Down
4 changes: 2 additions & 2 deletions toolkit/resources/manifests/package/pkggen_core_aarch64.txt
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,8 @@ zlib-devel-1.3.2-1.azl3.aarch64.rpm
file-5.45-1.azl3.aarch64.rpm
file-devel-5.45-1.azl3.aarch64.rpm
file-libs-5.45-1.azl3.aarch64.rpm
binutils-2.41-12.azl3.aarch64.rpm
binutils-devel-2.41-12.azl3.aarch64.rpm
binutils-2.41-13.azl3.aarch64.rpm
binutils-devel-2.41-13.azl3.aarch64.rpm
gmp-6.3.0-1.azl3.aarch64.rpm
gmp-devel-6.3.0-1.azl3.aarch64.rpm
mpfr-4.2.1-1.azl3.aarch64.rpm
Expand Down
4 changes: 2 additions & 2 deletions toolkit/resources/manifests/package/pkggen_core_x86_64.txt
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,8 @@ zlib-devel-1.3.2-1.azl3.x86_64.rpm
file-5.45-1.azl3.x86_64.rpm
file-devel-5.45-1.azl3.x86_64.rpm
file-libs-5.45-1.azl3.x86_64.rpm
binutils-2.41-12.azl3.x86_64.rpm
binutils-devel-2.41-12.azl3.x86_64.rpm
binutils-2.41-13.azl3.x86_64.rpm
binutils-devel-2.41-13.azl3.x86_64.rpm
gmp-6.3.0-1.azl3.x86_64.rpm
gmp-devel-6.3.0-1.azl3.x86_64.rpm
mpfr-4.2.1-1.azl3.x86_64.rpm
Expand Down
6 changes: 3 additions & 3 deletions toolkit/resources/manifests/package/toolchain_aarch64.txt
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,9 @@ bash-5.2.15-3.azl3.aarch64.rpm
bash-debuginfo-5.2.15-3.azl3.aarch64.rpm
bash-devel-5.2.15-3.azl3.aarch64.rpm
bash-lang-5.2.15-3.azl3.aarch64.rpm
binutils-2.41-12.azl3.aarch64.rpm
binutils-debuginfo-2.41-12.azl3.aarch64.rpm
binutils-devel-2.41-12.azl3.aarch64.rpm
binutils-2.41-13.azl3.aarch64.rpm
binutils-debuginfo-2.41-13.azl3.aarch64.rpm
binutils-devel-2.41-13.azl3.aarch64.rpm
bison-3.8.2-1.azl3.aarch64.rpm
bison-debuginfo-3.8.2-1.azl3.aarch64.rpm
bzip2-1.0.8-1.azl3.aarch64.rpm
Expand Down
10 changes: 5 additions & 5 deletions toolkit/resources/manifests/package/toolchain_x86_64.txt
Original file line number Diff line number Diff line change
Expand Up @@ -32,10 +32,10 @@ bash-5.2.15-3.azl3.x86_64.rpm
bash-debuginfo-5.2.15-3.azl3.x86_64.rpm
bash-devel-5.2.15-3.azl3.x86_64.rpm
bash-lang-5.2.15-3.azl3.x86_64.rpm
binutils-2.41-12.azl3.x86_64.rpm
binutils-aarch64-linux-gnu-2.41-12.azl3.x86_64.rpm
binutils-debuginfo-2.41-12.azl3.x86_64.rpm
binutils-devel-2.41-12.azl3.x86_64.rpm
binutils-2.41-13.azl3.x86_64.rpm
binutils-aarch64-linux-gnu-2.41-13.azl3.x86_64.rpm
binutils-debuginfo-2.41-13.azl3.x86_64.rpm
binutils-devel-2.41-13.azl3.x86_64.rpm
bison-3.8.2-1.azl3.x86_64.rpm
bison-debuginfo-3.8.2-1.azl3.x86_64.rpm
bzip2-1.0.8-1.azl3.x86_64.rpm
Expand Down Expand Up @@ -70,7 +70,7 @@ cracklib-lang-2.9.11-1.azl3.x86_64.rpm
createrepo_c-1.0.3-1.azl3.x86_64.rpm
createrepo_c-debuginfo-1.0.3-1.azl3.x86_64.rpm
createrepo_c-devel-1.0.3-1.azl3.x86_64.rpm
cross-binutils-common-2.41-12.azl3.noarch.rpm
cross-binutils-common-2.41-13.azl3.noarch.rpm
cross-gcc-common-13.2.0-7.azl3.noarch.rpm
curl-8.11.1-6.azl3.x86_64.rpm
curl-debuginfo-8.11.1-6.azl3.x86_64.rpm
Expand Down
Loading