CVE-2025-69649

HIGH

GNU Binutils < 2.46 - Denial of Service via Malformed ELF Header Processing

Title source: llm
STIX 2.1

Description

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 16.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
gnu/binutils < 2.46
Published Mar 06, 2026
Tracked Since Mar 07, 2026