Per [1] this is fixed in 2.47.
As a RedHat version-less CVE this is currently reported as
"Unpatched": "no-version-ranges".
[1] https://security-tracker.debian.org/tracker/CVE-2026-4647
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
UPSTREAM_CHECK_GITTAGREGEX = "binutils-(?P<pver>\d+_(\d_?)*)"
+CVE_STATUS[CVE-2026-4647] = "fixed-version: fixed-version: Fixed from version 2.47"
+
SRCREV ?= "6ce87bbc521cf46eaee9a1f7ef61cee2cdfb3e32"
BINUTILS_GIT_URI ?= "git://sourceware.org/git/binutils-gdb.git;branch=${SRCBRANCH};protocol=https"
SRC_URI = "\