PT-2026-23739 · Gnu+1 · Gnu Binutils+1

Published

2025-12-07

·

Updated

2026-05-06

·

CVE-2025-69649

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils versions through 2.46
Description The software contains a flaw where a null pointer dereference can occur when processing a specially crafted ELF binary with incorrectly formatted header fields. This happens during relocation processing when an invalid or null section pointer is passed to the display relocations() function, leading to a segmentation fault and program termination. No evidence suggests memory corruption beyond the null pointer dereference or the possibility of code execution.
Recommendations Update to a newer version of GNU Binutils than 2.46. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-79571
AZL-79595
BDU:2026-04341
CVE-2025-69649
ECHO-5E4D-8C97-615A
RHSA-2026:7098

Affected Products

Gnu Binutils
Red Os