CVE-2025-69644
published 2026-03-06CVE-2025-69644: An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug…
PriorityP417medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.13%
2.6th percentile
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | < 2.46 | 2.46 |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-69644: An issue was discovered in Binutils before 2
osv·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644: An issue was discovered in Binutils before 2
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
GHSA
GHSA-6j8w-mcjj-7669: An issue was discovered in Binutils before 2
ghsa_unreviewed·2026-03-06
CVE-2025-69644 [MEDIUM] CWE-400 GHSA-6j8w-mcjj-7669: An issue was discovered in Binutils before 2
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Microsoft
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling
vendor_msrc·2026-03-10·CVSS 5.0
CVE-2025-69644 [MEDIUM] CWE-400 An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
vendor_redhat·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CWE-606 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
A flaw was found in binutils. A local attacker can exploit a logic flaw in the handling of DWARF (Debugging With Attributed Record Formats) location list headers within the objdump utility. By supplying a crafted
Debian
CVE-2025-69644: binutils - An issue was discovered in Binutils before 2.46. The objdump contains a denial-o...
vendor_debian·2025·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644: binutils - An issue was discovered in Binutils before 2.46. The objdump contains a denial-o...
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-69644 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
bugzilla·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
CVE-2025-69644 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Bugzilla
CVE-2025-69644 radare2: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
bugzilla·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644 radare2: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
CVE-2025-69644 radare2: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69644 mingw-binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
bugzilla·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644 mingw-binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
CVE-2025-69644 mingw-binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback
Bugzilla
CVE-2025-69644 rizin: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
bugzilla·2026-03-06·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644 rizin: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
CVE-2025-69644 rizin: Binutils: Denial of Service via crafted binary with malformed DWARF debug information [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Wiz
CVE-2025-69644 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.0
CVE-2025-69644 [MEDIUM] CVE-2025-69644 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69644 :
NixOS vulnerability analysis and mitigation
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Source : NVD
## 5
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
NixOS
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabili
2026-03-06
Published