The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
Multiple Denial-of-Service Vulnerabilities in GNU Binutils Disclosed A series of denial-of-service vulnerabilities affecting GNU Binutils versions up to 2.46 have been disclosed. These vulnerabilities, identified as CVE-2025-69644, CVE-2025-69645, CVE-2025-69646, CVE-2025-69650, CVE-2025-69651, and CVE-2025-69652, can be triggered by processing crafted ELF binaries or malformed DWARF debug information, leading to program crashes or unbounded logging loops. All vulnerabilities were published on March 6, 2026, and affect local users who can supply malicious input files.