CVE-2025-69647: GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

Overview

Severity
Medium (CVSS 6.2)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploit Status
Not Exploited
Patch Tuesday
2026-Mar
Released
2026-03-15
Last Updated
2026-04-14
EPSS Score
0.15% (percentile: 4.7%)

Affected Products (3)

Open Source Software

  • cbl2 binutils 2.37-20 on CBL Mariner 2.0
  • azl3 binutils 2.41-10 on Azure Linux 3.0

Other

  • 21200-17084

Revision History

  • 2026-03-15: Information published.
  • 2026-03-16: Information published.
  • 2026-03-17: Information published.
  • 2026-04-14: Information published.
  • 2026-04-14: Information published.