PT-2026-23730 · Gnu · Binutils

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2025-69646

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Binutils version 2.44
Description Binutils objdump is subject to a denial-of-service condition when processing a specially crafted binary file containing malformed DWARF debug rnglists data. A flaw in how the debug rnglists header is processed can cause objdump to enter an infinite loop, repeatedly printing the same warning message and preventing normal termination. This results in excessive CPU and I/O usage, potentially halting the objdump analysis. A local attacker can trigger this by providing a malicious input file.
Recommendations Update to a newer version of Binutils that addresses this issue.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-79559
AZL-79583
CVE-2025-69646
ECHO-3C7E-9799-1DBC
RHSA-2026:7098

Affected Products

Binutils