Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79826.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-79826
Upstream
Published
2026-03-09T15:15:50Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2025-69647 affecting package binutils for versions less than 2.41-11
Details

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

References

Affected packages

Azure Linux:3 / binutils

Package

Name
binutils
Purl
pkg:rpm/azure-linux/binutils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.41-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79826.json"