CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-69649: GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

mediumCVSS 5.5CVE-2025-69649

CSIRTS triage

What
Null pointer dereference in readelf when processing crafted ELF binaries with malformed headers during relocation processing.
Who is affected
Users of GNU Binutils readelf tool version 2.46 and earlier processing untrusted ELF binaries.
Urgency
Medium urgency; CVSS 5.5 indicates moderate impact, likely causing application crash rather than escalation.
Action
Update GNU Binutils to a version after 2.46 with the fix applied.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Binutils

Get an email when a new Binutils advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-69649

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-69649coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center