CVE-2025-69648

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*

History

13 Mar 2026, 16:43

Type Values Removed Values Added
First Time Gnu
Gnu binutils
CPE cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
References () https://sourceware.org/bugzilla/show_bug.cgi?id=33641 - () https://sourceware.org/bugzilla/show_bug.cgi?id=33641 - Exploit, Third Party Advisory
References () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 - () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33 - Patch

10 Mar 2026, 18:18

Type Values Removed Values Added
Summary
  • (es) GNU Binutils hasta la versión 2.45.1 readelf contiene una vulnerabilidad de denegación de servicio al procesar un binario manipulado con datos DWARF .debug_rnglists malformados. Un fallo lógico en la ruta de análisis DWARF provoca que readelf imprima repetidamente el mismo mensaje de advertencia sin avanzar, lo que resulta en un bucle de salida no terminante que requiere interrupción manual. No se observó evidencia de corrupción de memoria ni ejecución de código.
CWE CWE-835
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

09 Mar 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 15:15

Updated : 2026-03-13 16:43


NVD link : CVE-2025-69648

Mitre link : CVE-2025-69648

CVE.ORG link : CVE-2025-69648


JSON object : View

Products Affected

gnu

  • binutils
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')