CVE-2025-69649: GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

Overview

Severity
Medium (CVSS 5.5)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploit Status
Not Exploited
Patch Tuesday
2026-Mar
Released
2026-03-11
EPSS Score
0.03% (percentile: 8.4%)

Affected Products (2)

Open Source Software

  • azl3 binutils 2.41-10 on Azure Linux 3.0
  • cbl2 binutils 2.37-20 on CBL Mariner 2.0

Revision History

  • 2026-03-11: Information published.