{"id":"RLSA-2023:6236","summary":"Moderate: binutils security update","details":"The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings, strip, and addr2line utilities.\n\nSecurity Fix(es):\n\n* binutils: NULL pointer dereference in _bfd_elf_get_symbol_version_string leads to segfault (CVE-2022-4285)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-03-11T06:25:59.944033Z","published":"2023-11-11T22:59:34.304122Z","upstream":["CVE-2022-4285"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2023:6236"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2150768"}],"affected":[{"package":{"name":"binutils","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/binutils?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.30-119.el8_8.2"}],"database_specific":{"yum_repository":"BaseOS"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2023:6236.json"}}],"schema_version":"1.7.5","credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}