Denial of Service Vulnerability in GNU Binutils Affects Multiple Versions
CVE-2025-69652
What is CVE-2025-69652?
GNU Binutils versions 2.46 and earlier contain a vulnerability that can cause a Denial of Service (DoS) through improper handling of malformed DWARF attributes in ELF binaries. When the readelf tool processes these malformed binaries, it encounters an incomplete state transition in the debugging information parsing routine, leading to a fatal abort (SIGABRT). This occurs due to an invalid state propagating during the processing of DWARF attribute lengths, ultimately triggering an unexpected data length of zero in specific cases. While there is no indication of memory corruption or arbitrary code execution, this flaw results in service disruption, making it critical for users and developers to update their systems to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved