CVE-2025-69647Disclosure(gnu / binutils)

LOWCVSS 6.2 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • binutils

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
binutils

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-09: 3Technical Details · 2026-03-09: 303-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69647 Denial-of-Service Vulnerability in GNU Binutils readelf v... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69647 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2025-69647, a denial‑of‑service flaw in GNU Binutils readelf, and provides a link for more information, without any evidence of exploitation, patching, or false‑positive claims.

    0001158
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-69647 GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the D… https://www.cve.org/CVERecord?id=CVE-2025-69647 ----- Traducción: CVE-2025-69647 GNU… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2025‑69647, a denial‑of‑service vulnerability in GNU Binutils readelf caused by malformed DWARF loclists data, and provides a link to the CVE record.

    0000065
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69647 GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the D… https://www.cve.org/CVERecord?id=CVE-2025-69647

    Post summary

    The message announces a DoS vulnerability (CVE‑2025‑69647) in GNU Binutils’ readelf, detailing how crafted DWARF loclists can trigger the flaw, but offers no PoC, exploit, or mitigation.

    00000200
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnubinutils---

Explore more