cbcvebase.
CVE-2025-69644
published 2026-03-06

CVE-2025-69644: An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug…

PriorityP417medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.13%
2.6th percentile
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianbinutils
gnubinutils< 2.462.46
msrcazl3_binutils_2.41-10_on_azure_linux_3.0
msrccbl2_binutils_2.37-20_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.