PT-2026-23730 · Gnu · Binutils
Published
2026-03-06
·
Updated
2026-03-11
·
CVE-2025-69646
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Binutils version 2.44
Description
Binutils objdump is subject to a denial-of-service condition when processing a specially crafted binary file containing malformed DWARF debug rnglists data. A flaw in how the debug rnglists header is processed can cause objdump to enter an infinite loop, repeatedly printing the same warning message and preventing normal termination. This results in excessive CPU and I/O usage, potentially halting the objdump analysis. A local attacker can trigger this by providing a malicious input file.
Recommendations
Update to a newer version of Binutils that addresses this issue.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Binutils