CVE-2025-69649

Published: March 11, 2026Last modified: March 28, 2026

Description

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbinutilsUnknown (2.39-r2)
25 LTSbinutilsFixed (2.45.1-r1)
StreambinutilsFixed (2.45.1-r3)
Hardened Containers23 LTSbinutilsUnknown (2.39-r2)
25 LTSbinutilsFixed (2.45.1-r1)
StreambinutilsFixed (2.45.1-r3)

References

ON THIS PAGE