CVE-2025-69649: Null Pointer Dereference
GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into displayrelocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-11
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69649?
CVE-2025-69649 has a severity rating that indicates it can lead to a segmentation fault when processing malformed ELF binaries.
How do I fix CVE-2025-69649?
To fix CVE-2025-69649, update GNU Binutils to a version later than 2.46 where the vulnerability is resolved.
What happens if I exploit CVE-2025-69649?
Exploiting CVE-2025-69649 may cause the program to crash due to a segmentation fault when processing an invalid ELF binary.
Which versions of GNU Binutils are affected by CVE-2025-69649?
CVE-2025-69649 affects GNU Binutils versions up to and including 2.46.
How can I prevent CVE-2025-69649 from affecting my system?
To prevent CVE-2025-69649, ensure that your system runs an updated version of GNU Binutils beyond version 2.46.