Denial of Service Vulnerability in GNU Binutils Affects Multiple Versions
CVE-2025-69652

6.2MEDIUM

Key Information:

Vendor

GNU

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2025-69652?

GNU Binutils versions 2.46 and earlier contain a vulnerability that can cause a Denial of Service (DoS) through improper handling of malformed DWARF attributes in ELF binaries. When the readelf tool processes these malformed binaries, it encounters an incomplete state transition in the debugging information parsing routine, leading to a fatal abort (SIGABRT). This occurs due to an invalid state propagating during the processing of DWARF attribute lengths, ultimately triggering an unexpected data length of zero in specific cases. While there is no indication of memory corruption or arbitrary code execution, this flaw results in service disruption, making it critical for users and developers to update their systems to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.