CVE-2025-69647

Source
https://cve.org/CVERecord?id=CVE-2025-69647
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69647.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69647
Downstream
Published
2026-03-09T15:15:50.740Z
Modified
2026-03-15T14:53:36.483076Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
48324fde1e284293dd3d570dba597cb644921c92
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.45.1"
        }
    ]
}

Affected versions

Other
binu_ss_19990502
binutils-2_41-release
binutils-2_45
binutils-2_45_1
gdb-10-branchpoint
gdb-11-branchpoint
gdb-12-branchpoint
gdb-13-branchpoint
gdb-14-branchpoint
gdb-15-branchpoint
gdb-16-branchpoint
gdb-4_18-branchpoint
gdb-9-branchpoint
gdb_5_2-branchpoint
gdb_5_3-branchpoint
gdb_6_0-branchpoint
gdb_6_1-branchpoint
gdb_6_2-branchpoint
gdb_6_3-branchpoint
gdb_6_4-branchpoint
gdb_6_5-branchpoint
gdb_6_6-branchpoint
gdb_6_7-branchpoint
gdb_6_8-branchpoint
gdb_7_0-branchpoint
gdb_7_1-branchpoint
gdb_7_2-branchpoint
gdb_7_3-branchpoint
gdb_7_4-branchpoint
gdb_7_5-branchpoint
gdb_7_6-branchpoint
readline_4_0
users/ARM/embedded-binutils-master-2016q4
users/ARM/embedded-binutils-master-2017q4
users/ARM/embedded-binutils-master-2018q4
users/ARM/embedded-gdb-master-2017q4
users/ARM/embedded-gdb-master-2018q4
gdb-7.*
gdb-7.10-branchpoint
gdb-7.11-branchpoint
gdb-7.12-branchpoint
gdb-7.7-branchpoint
gdb-7.8-branchpoint
gdb-7.9-branchpoint
gdb-8.*
gdb-8.0-branchpoint
gdb-8.1-branchpoint
gdb-8.2-branchpoint
gdb-8.3-branchpoint

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69647.json"