binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information
Published Mar 6, 2026
6.2
MEDIUMCVSS 3.1
EPSS 0.17%
Description
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.
Affected products
No data.
No data.
Red Hat Hardened Images
binutils-main-2.45.1-5.hum1
Fixed · RHSA-2026:7098
Red Hat Enterprise Linux 10
binutils
Fix deferred
Red Hat Enterprise Linux 10
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 10
gdb
Fix deferred
Red Hat Enterprise Linux 10
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 6
binutils
Fix deferred
Red Hat Enterprise Linux 7
binutils
Fix deferred
Red Hat Enterprise Linux 7
gdb
Fix deferred
Red Hat Enterprise Linux 8
binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-14-gdb
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-15-gdb
Fix deferred
Red Hat Enterprise Linux 8
gdb
Fix deferred
Red Hat Enterprise Linux 8
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-14-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-15-binutils
Fix deferred
Red Hat Enterprise Linux 9
gdb
Fix deferred
Red Hat Enterprise Linux 9
mingw-binutils
Fix deferred
Red Hat OpenShift Container Platform 4
rhcos
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | binutils-main-2.45.1-5.hum1 | Fixed | RHSA-2026:7098 |
| Red Hat Enterprise Linux 10 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-14-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-15-gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-14-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-15-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gdb | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this reachable abort is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with readelf. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.
Red Hat mitigation
To mitigate this vulnerability, do not process untrusted, unverified or externally supplied ELF binaries with the readelf program.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Mar 9, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.17% (0.00173) | 5.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.17% (0.00173) | 6.92th | v5 (v2026.06.15) |
| Mar 7, 2026 | 0.02% (0.00022) | 5.68th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2025-69652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2445296 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-69652
- https://sourceware.org/bugzilla/show_bug.cgi?id=33701 ExploitThird Party Advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01 Patch
- https://www.cve.org/CVERecord?id=CVE-2025-69652
Change history (0)
No recorded changes yet.