CVE-2025-69646

Severity
5.5MEDIUM
EPSS
0.0%
top 99.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 6
Latest updateMar 10

Description

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive …

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

ā–¶NVDgnu/binutils2.44

šŸ”“Vulnerability Details

3
OSV
CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data↗2026-03-06
ā–¶
CVEList
CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data↗2026-03-06
ā–¶
GHSA
GHSA-q7mh-pw55-9h55: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data↗2026-03-06
ā–¶

šŸ“‹Vendor Advisories

3
Microsoft
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can ca↗2026-03-10
ā–¶
Red Hat
binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data↗2026-03-06
ā–¶
Debian
CVE-2025-69646: binutils - Binutils objdump contains a denial-of-service vulnerability when processing a cr...↗2025
ā–¶

šŸ•µļøThreat Intelligence

1
Wiz
CVE-2025-69646 Impact, Exploitability, and Mitigation Steps | Wiz↗
ā–¶

šŸ’¬Community

1
Bugzilla
CVE-2025-69646 mingw-binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]↗2026-03-06
ā–¶
CVE-2025-69646 (MEDIUM CVSS 5.5) | Binutils objdump contains a denial- | cvebase.io