[Low] patch binutils for CVE-2025-1147, CVE-2025-1148, CVE-2025-11839#15458
[Low] patch binutils for CVE-2025-1147, CVE-2025-1148, CVE-2025-11839#15458jykanase wants to merge 2 commits intomicrosoft:3.0-devfrom
Conversation
1ca0deb to
e5c4a10
Compare
e5c4a10 to
1f8bd38
Compare
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Patch Analysis (the patch applies cleanly)
Fix for SPECS/binutils/CVE-2025-1148.patch has been taken from Ubuntu as binutils have not released any patch for it yet.
Although the diff shows indentation differences but the developer has applied the patch by patching command and its getting build as well. LGTM
- Buddy Build
- patch applied during the build (check
rpm.log) - patch include an upstream reference
- PR has security tag
@Kanishk-Bansal Thanks for the details. Can you please consider following checks too?
|
|
Patches apply cleanly and no backporting has been done |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
patch binutils for CVE-2025-1147, CVE-2025-1148, CVE-2025-11839
Patch Modified: No
CVE-2025-1147 : https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=7be4186c22f89a87fff048c28910f5d26a0f61ce
CVE-2025-1148 : https://git.launchpad.net/ubuntu/+source/binutils/diff/debian/patches/CVE-2025-1148.patch?id=23551b7f3c0a1881dabbe2051d639bee43261514
CVE-2025-11839 : https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=12ef7d5b7b02d0023db645d86eb9d0797bc747fe
Change Log
Does this affect the toolchain?
YES
Associated issues
Links to CVEs
Test Methodology