<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2026-0057</id>
    <title>An update for gdb is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2026-03-23 23:18:31"/>
    <updated date="2026-03-23 23:18:31"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11494" id="CVE-2025-11494" title="CVE-2025-11494 Base Score: 5.5 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11412" id="CVE-2025-11412" title="CVE-2025-11412 Base Score: 5.5 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11840" id="CVE-2025-11840" title="CVE-2025-11840 Base Score: 5.5 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2021-32256" id="CVE-2021-32256" title="CVE-2021-32256 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-11082" id="CVE-2025-11082" title="CVE-2025-11082 Base Score: 7.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue. (CVE-2025-11494)

A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch. (CVE-2025-11412)

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue. (CVE-2025-11840)

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c. (CVE-2021-32256)

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with &quot;[f]ixed for 2.46&quot;. (CVE-2025-11082)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="gdb">
        <name>HCE 2.0</name>
        <package arch="x86_64" name="gdb" version="11.1" release="1.r11.hce2">
          <filename>gdb-11.1-1.r11.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="gdb-gdbserver" version="11.1" release="1.r11.hce2">
          <filename>gdb-gdbserver-11.1-1.r11.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="gdb-headless" version="11.1" release="1.r11.hce2">
          <filename>gdb-headless-11.1-1.r11.hce2.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="gdb-help" version="11.1" release="1.r11.hce2">
          <filename>gdb-help-11.1-1.r11.hce2.noarch.rpm</filename>
        </package>
        <package arch="aarch64" name="gdb" version="11.1" release="1.r11.hce2">
          <filename>gdb-11.1-1.r11.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="gdb-gdbserver" version="11.1" release="1.r11.hce2">
          <filename>gdb-gdbserver-11.1-1.r11.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="gdb-headless" version="11.1" release="1.r11.hce2">
          <filename>gdb-headless-11.1-1.r11.hce2.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
