PT-2026-23741 · Gnu+1 · Gnu Binutils+1
Published
2025-12-07
·
Updated
2026-05-06
·
CVE-2025-69652
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils versions through 2.46
Description
The software contains a flaw that can cause it to stop working unexpectedly (SIGABRT) when it processes a specially crafted ELF binary file with incorrectly formatted DWARF abbrev or debug information. This happens because of incomplete cleanup within the
process debug info() function, which can lead to an invalid state being used by routines that parse DWARF attributes. Specifically, when a malformed attribute results in a zero data length, the byte get little endian() function triggers the fatal abort. The issue is limited to a denial-of-service condition, with no observed memory corruption or code execution.Recommendations
Update to a version of GNU Binutils later than 2.46.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Binutils
Red Os