CVE-2025-69647
published 2026-03-09CVE-2025-69647: GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw…
PriorityP424medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.15%
4.6th percentile
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | <= 2.45.1 | — |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2LOW
vendor_msrc6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqfr-x96j-g24p: GNU Binutils thru 2
ghsa_unreviewed·2026-03-09
CVE-2025-69647 [MEDIUM] CWE-835 GHSA-pqfr-x96j-g24p: GNU Binutils thru 2
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
OSV
CVE-2025-69647: GNU Binutils thru 2
osv·2026-03-09·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647: GNU Binutils thru 2
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Microsoft
CVE-2025-69647: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
vendor_redhat·2026-03-09·CVSS 6.2
CVE-2025-69647 [MEDIUM] CWE-835 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed DWARF loclists data with the readelf program can trigger an infinite loop
Debian
CVE-2025-69647: binutils - GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when...
vendor_debian·2025·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647: binutils - GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when...
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-69647 radare2: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647 radare2: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
CVE-2025-69647 radare2: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69647 rizin: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647 rizin: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
CVE-2025-69647 rizin: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69647 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
CVE-2025-69647 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback for th
Bugzilla
CVE-2025-69647 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
bugzilla·2026-03-09·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
CVE-2025-69647 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Wiz
CVE-2025-69647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2025-69647 [MEDIUM] CVE-2025-69647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69647 :
NixOS vulnerability analysis and mitigation
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Source : NVD
## 6.2
Score
Published March 9, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
NixOS
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date
2026-03-09
Published