<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2025-0183</id>
    <title>An update for binutils is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2025-06-25 17:09:25"/>
    <updated date="2025-06-25 17:09:25"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-5245" id="CVE-2025-5245" title="CVE-2025-5245 Base Score: 5.3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-5244" id="CVE-2025-5244" title="CVE-2025-5244 Base Score: 5.3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" type="cve"/>
    </references>
    <description>Security Fix(es):

A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. (CVE-2025-5245)

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component. (CVE-2025-5244)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="binutils">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="binutils" version="2.37" release="6.r29.hce2">
          <filename>binutils-2.37-6.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="binutils-devel" version="2.37" release="6.r29.hce2">
          <filename>binutils-devel-2.37-6.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="binutils-extra" version="2.37" release="6.r29.hce2">
          <filename>binutils-extra-2.37-6.r29.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="binutils" version="2.37" release="6.r29.hce2">
          <filename>binutils-2.37-6.r29.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="binutils-devel" version="2.37" release="6.r29.hce2">
          <filename>binutils-devel-2.37-6.r29.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="binutils-extra" version="2.37" release="6.r29.hce2">
          <filename>binutils-extra-2.37-6.r29.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
