CVE-2025-69648
published 2026-03-09CVE-2025-69648: GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic…
PriorityP424medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.18%
7.1th percentile
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | <= 2.45.1 | — |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_msrc7.4HIGH
vendor_debian6.2LOW
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x33-566w-9pg7: GNU Binutils thru 2
ghsa_unreviewed·2026-03-09
CVE-2025-69648 [MEDIUM] CWE-835 GHSA-4x33-566w-9pg7: GNU Binutils thru 2
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
OSV
CVE-2025-69648: GNU Binutils thru 2
osv·2026-03-09·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648: GNU Binutils thru 2
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Microsoft
CVE-2025-69648: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 7.4
CVE-2025-69648 [MEDIUM] CVE-2025-69648: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
vendor_redhat·2026-03-09·CVSS 6.2
CVE-2025-69648 [MEDIUM] CWE-835 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
A flaw was found in binutils. Processing a specially crafted ELF binary file containing malformed DWARF .debug_rnglists data with the readelf program can trigger an infinite loop and result in a denial of service.
Statement: This issue is classified with a low severity prim
Debian
CVE-2025-69648: binutils - GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when...
vendor_debian·2025·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648: binutils - GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when...
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-69648 rizin: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648 rizin: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
CVE-2025-69648 rizin: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69648 radare2: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648 radare2: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
CVE-2025-69648 radare2: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69648 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
bugzilla·2026-03-16·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
CVE-2025-69648 mingw-binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback
Bugzilla
CVE-2025-69648 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
bugzilla·2026-03-09·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
CVE-2025-69648 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Wiz
CVE-2025-69648 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2025-69648 [MEDIUM] CVE-2025-69648 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69648 :
NixOS vulnerability analysis and mitigation
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Source : NVD
## 6.2
Score
Published March 9, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
NixOS
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3
Exploitation Probability (EPSS) N/A
2026-03-09
Published