binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data
Published Mar 9, 2026
6.2
MEDIUMCVSS 3.1
EPSS 0.15%
Description
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.
Affected products
No data.
No data.
Red Hat Hardened Images
binutils-main-2.45.1-5.hum1
Fixed · RHSA-2026:7098
Red Hat Enterprise Linux 10
binutils
Fix deferred
Red Hat Enterprise Linux 10
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 10
gdb
Fix deferred
Red Hat Enterprise Linux 10
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 6
binutils
Fix deferred
Red Hat Enterprise Linux 7
binutils
Fix deferred
Red Hat Enterprise Linux 7
gdb
Fix deferred
Red Hat Enterprise Linux 8
binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-gdb
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-gdb
Fix deferred
Red Hat Enterprise Linux 8
gdb
Fix deferred
Red Hat Enterprise Linux 8
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 9
gdb
Fix deferred
Red Hat Enterprise Linux 9
mingw-binutils
Fix deferred
Red Hat OpenShift Container Platform 4
rhcos
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | binutils-main-2.45.1-5.hum1 | Fixed | RHSA-2026:7098 |
| Red Hat Enterprise Linux 10 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this infinite loop is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with readelf. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.
Red Hat mitigation
To mitigate this vulnerability, do not process untrusted, unverified or externally supplied ELF binaries with the readelf program.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Mar 10, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00152) | 3.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.15% (0.00152) | 4.67th | v5 (v2026.06.15) |
| Mar 10, 2026 | 0.02% (0.00021) | 5.38th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2025-69647 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2445773 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-69647
- https://sourceware.org/bugzilla/show_bug.cgi?id=33640 ExploitThird Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7 Patch
- https://www.cve.org/CVERecord?id=CVE-2025-69647
Change history (0)
No recorded changes yet.