CVE-2025-69651
published 2026-03-06CVE-2025-69651: GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.24%
15.0th percentile
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | <= 2.46 | — |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_msrc7.1HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-69651: GNU Binutils thru 2
osv·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651: GNU Binutils thru 2
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.
GHSA
GHSA-v4pr-w75g-wfrf: GNU Binutils thru 2
ghsa_unreviewed·2026-03-06
CVE-2025-69651 [MEDIUM] CWE-476 GHSA-v4pr-w75g-wfrf: GNU Binutils thru 2
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.
Microsoft
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns
vendor_msrc·2026-03-10·CVSS 7.1
CVE-2025-69651 [MEDIUM] GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
binutils: Binutils: Denial of Service via crafted ELF binary processing
vendor_redhat·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CWE-824 binutils: Binutils: Denial of Service via crafted ELF binary processing
binutils: Binutils: Denial of Service via crafted ELF binary processing
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any
Debian
CVE-2025-69651: binutils - GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid...
vendor_debian·2025·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651: binutils - GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid...
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.
Scope: local
bookworm: open
bullseye: open
forky: open
s
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-69651 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69651 :
NixOS vulnerability analysis and mitigation
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged
Bugzilla
CVE-2025-69651 rizin: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651 rizin: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
CVE-2025-69651 rizin: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69651 binutils: Binutils: Denial of Service via crafted ELF binary processing
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651 binutils: Binutils: Denial of Service via crafted ELF binary processing
CVE-2025-69651 binutils: Binutils: Denial of Service via crafted ELF binary processing
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.
Bugzilla
CVE-2025-69651 radare2: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651 radare2: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
CVE-2025-69651 radare2: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69651 mingw-binutils: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69651 [MEDIUM] CVE-2025-69651 mingw-binutils: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
CVE-2025-69651 mingw-binutils: Binutils: Denial of Service via crafted ELF binary processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback for this update here: h
https://sourceware.org/bugzilla/show_bug.cgi?id=33698https://sourceware.org/bugzilla/show_bug.cgi?id=33700https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921
2026-03-06
Published