RHSA-2026:7098MediumCVSS 5.3

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 8, 2026
Last Modified
July 19, 2026

🔗 CVE IDs covered (25)

CVE-2025-11494CVE-2025-11495CVE-2025-11839CVE-2025-66863CVE-2025-66864CVE-2025-69646 · pendingCVE-2025-11081CVE-2025-11412CVE-2025-11413CVE-2025-11840CVE-2025-66861CVE-2025-66866CVE-2025-69645 · pendingCVE-2025-69647 · pendingCVE-2025-69644 · pendingCVE-2025-69648 · pendingCVE-2025-69652 · pendingCVE-2025-11083CVE-2025-66862CVE-2025-66865CVE-2025-69649 · pendingCVE-2025-69650 · pendingCVE-2025-69651 · pendingCVE-2025-11082CVE-2025-11414

📋 Description

CVE-2025-11081 — binutils: GNU Binutils out-of-bounds read CVE-2025-11082 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11083 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11412 — binutils: GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds CVE-2025-11413 — binutils: GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds CVE-2025-11414 — binutils: GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds CVE-2025-11494 — binutils: GNU Binutils Linker out-of-bounds read CVE-2025-11495 — binutils: GNU Binutils Linker heap-based overflow CVE-2025-11839 — binutils: GNU Binutils prdbg.c tg_tag_type return value CVE-2025-11840 — binutils: GNU Binutils out-of-bounds read CVE-2025-66861 — binutils: out-of-bounds read in d_unqualified_name() in cp-demangle.c CVE-2025-66862 — binutils: heap-based buffer over-read in gnu_special() in cplus-dem.c CVE-2025-66863 — binutils: BinUtils: Denial of Service via crafted PE file CVE-2025-66864 — binutils: NULL pointer dereference in d_print_comp_inner() in cp-demangle.c CVE-2025-66865 — binutils: stack overflow in d_print_comp_inner() in cp-demangle.c CVE-2025-66866 — binutils: BinUtils: Denial of Service via crafted PE file CVE-2025-69644 — binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information CVE-2025-69645 — binutils: Binutils objdump: Denial of Service via crafted DWARF debug information CVE-2025-69646 — binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data CVE-2025-69647 — binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data CVE-2025-69648 — binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data CVE-2025-69649 — binutils: NULL pointer dereference in readelf via crafted ELF binary with malformed header fields CVE-2025-69650 — binutils: double free in readelf via crafted ELF binary with malformed relocation data CVE-2025-69651 — binutils: Binutils: Denial of Service via crafted ELF binary processing CVE-2025-69652 — binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

🔗 References (29)