Bug 2445298 (CVE-2025-69649) - CVE-2025-69649 binutils: NULL pointer dereference in readelf via crafted ELF binary with malformed header fields
Summary: CVE-2025-69649 binutils: NULL pointer dereference in readelf via crafted ELF ...
Keywords:
Status: NEW
Alias: CVE-2025-69649
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2448121 2448122 2448127 2448128 2448123 2448124 2448125 2448126
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-06 19:01 UTC by OSIDB Bzimport
Modified: 2026-03-16 17:56 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-06 19:01:49 UTC
GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.


Note You need to log in before you can comment on or make changes to this bug.