CVE-2025-69646
published 2026-03-06CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.9th percentile
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | — | — |
| msrc | azl3_binutils_2.41-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_binutils_2.37-20_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data
osv·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
GHSA
GHSA-q7mh-pw55-9h55: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data
ghsa_unreviewed·2026-03-06
CVE-2025-69646 [MEDIUM] CWE-400 GHSA-q7mh-pw55-9h55: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Microsoft
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can ca
vendor_msrc·2026-03-10·CVSS 5.5
CVE-2025-69646 [MEDIUM] CWE-400 Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can ca
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
vendor_redhat·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CWE-606 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
A flaw was found in binutils. A local attacker can exploit this vulnerability by supplying a malicious input file containing malformed DWARF debug_rngl
Debian
CVE-2025-69646: binutils - Binutils objdump contains a denial-of-service vulnerability when processing a cr...
vendor_debian·2025·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646: binutils - Binutils objdump contains a denial-of-service vulnerability when processing a cr...
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-69646 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
CVE-2025-69646 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Bugzilla
CVE-2025-69646 radare2: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646 radare2: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
CVE-2025-69646 radare2: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2025-69646 mingw-binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646 mingw-binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
CVE-2025-69646 mingw-binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-9174e6ea37 (mingw-binutils-2.45.1-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9174e6ea37
---
FEDORA-2026-9174e6ea37 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-9174e6ea37`
You can provide feedback for this update h
Bugzilla
CVE-2025-69646 rizin: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
bugzilla·2026-03-06·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646 rizin: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
CVE-2025-69646 rizin: Binutils: Denial of Service via malformed DWARF debug_rnglists data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Wiz
CVE-2025-69646 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-69646 [MEDIUM] CVE-2025-69646 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69646 :
NixOS vulnerability analysis and mitigation
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Source : NVD
## 5.5
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
NixOS
Wolfi
Has Public Exploit Yes
Has CISA KEV Ex
2026-03-06
Published