CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-69647: GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage

mediumCVSS 6.2CVE-2025-69647

CSIRTS triage

What
A logic flaw in DWARF loclists parsing causes readelf to enter an infinite loop, printing output repeatedly without progress.
Who is affected
Systems using readelf to process untrusted or malformed ELF binaries with DWARF debug data.
Urgency
Medium priority; attackers can cause denial of service via crafted binaries, though impact is local.
Action
Update GNU Binutils to a version that fixes the DWARF loclists parsing logic.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Binutils

Get an email when a new Binutils advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 6.2
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-69647

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-69647coverage & exploitation statusNVD · CVE.org

Recent advisories for GNU Binutils thru

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center