PT-2026-23741 · Gnu+1 · Gnu Binutils+1

Published

2025-12-07

·

Updated

2026-05-06

·

CVE-2025-69652

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions through 2.46
Description The software contains a flaw that can cause it to stop working unexpectedly (SIGABRT) when it processes a specially crafted ELF binary file with incorrectly formatted DWARF abbrev or debug information. This happens because of incomplete cleanup within the process debug info() function, which can lead to an invalid state being used by routines that parse DWARF attributes. Specifically, when a malformed attribute results in a zero data length, the byte get little endian() function triggers the fatal abort. The issue is limited to a denial-of-service condition, with no observed memory corruption or code execution.
Recommendations Update to a version of GNU Binutils later than 2.46.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

AZL-79565
AZL-79589
BDU:2026-04682
CVE-2025-69652
ECHO-A5D8-A272-4241
RHSA-2026:7098

Affected Products

Gnu Binutils
Red Os