CVE-2025-69647

Name
CVE-2025-69647
Description
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://sourceware.org/bugzilla/show_bug.cgi?id=33640
cve@mitre.org https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* binutils >= None <= 2.45.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
binutils edge-main 2.45.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.45.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.45-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.44-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.43.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.40-r12 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r11 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r10 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r8 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r7 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r6 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.40-r0 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r3 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r2 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r1 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils edge-main 2.39-r0 None possibly vulnerable
binutils edge-main 2.35.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.35.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils edge-main 2.32-r0 None possibly vulnerable
binutils edge-main 2.28-r1 None possibly vulnerable
binutils 3.23-main 2.45.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.44-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.22-main 2.40-r10 None possibly vulnerable
binutils 3.22-main 2.40-r0 None possibly vulnerable
binutils 3.22-main 2.39-r2 None possibly vulnerable
binutils 3.22-main 2.39-r0 None possibly vulnerable
binutils 3.22-main 2.35.2-r1 None possibly vulnerable
binutils 3.22-main 2.32-r0 None possibly vulnerable
binutils 3.22-main 2.28-r1 None possibly vulnerable
binutils 3.21-main 2.43.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.43.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.43.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.21-main 2.40-r10 None possibly vulnerable
binutils 3.21-main 2.40-r0 None possibly vulnerable
binutils 3.21-main 2.39-r2 None possibly vulnerable
binutils 3.21-main 2.39-r0 None possibly vulnerable
binutils 3.21-main 2.35.2-r1 None possibly vulnerable
binutils 3.21-main 2.32-r0 None possibly vulnerable
binutils 3.21-main 2.28-r1 None possibly vulnerable
binutils 3.20-main 2.42-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.20-main 2.42-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.20-main 2.40-r10 None possibly vulnerable
binutils 3.20-main 2.40-r0 None possibly vulnerable
binutils 3.20-main 2.39-r2 None possibly vulnerable
binutils 3.20-main 2.39-r0 None possibly vulnerable
binutils 3.20-main 2.35.2-r1 None possibly vulnerable
binutils 3.20-main 2.32-r0 None possibly vulnerable
binutils 3.20-main 2.28-r1 None possibly vulnerable
binutils 3.19-main 2.41-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.19-main 2.41-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
binutils 3.19-main 2.40-r10 None possibly vulnerable
binutils 3.19-main 2.40-r0 None possibly vulnerable
binutils 3.19-main 2.39-r2 None possibly vulnerable
binutils 3.19-main 2.39-r0 None possibly vulnerable
binutils 3.19-main 2.35.2-r1 None possibly vulnerable
binutils 3.19-main 2.32-r0 None possibly vulnerable
binutils 3.19-main 2.28-r1 None possibly vulnerable