Back

MEDIUM

binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

Published Mar 9, 2026

Description

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

Affected products

Remediation

Red Hat statement

This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this infinite loop is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with readelf. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Red Hat mitigation

To mitigate this vulnerability, do not process untrusted, unverified or externally supplied ELF binaries with the readelf program.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 9, 2026
Updated Mar 10, 2026
Reserved Jan 9, 2026
CISA Vulnrichment
Updated Mar 10, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 9, 2026