CVE-2025-66862: Buffer Overflow
Published Dec 29, 2025
·Updated
A buffer overflow vulnerability in function gnuspecial in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
Affected Software
4 affected components
GNU binutils
GNU binutils=2.26
F5 F5OS-A>=1.8.0<=1.8.3, >=1.5.1<=1.5.4
F5 F5OS-C>=1.8.0<=1.8.2, >=1.6.0<=1.6.4
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 3, 2026
Advisory Published
via F5·04:32 PM
Data Sourced
via F5·04:32 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66862?
The severity of CVE-2025-66862 is classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2025-66862?
To fix CVE-2025-66862, you should upgrade to a patched version of BinUtils or apply available security patches provided by the vendor.
3
Who is affected by CVE-2025-66862?
CVE-2025-66862 affects users of BinUtils version 2.26 or earlier who process crafted PE files.
4
What type of vulnerability is CVE-2025-66862?
CVE-2025-66862 is a buffer overflow vulnerability found in the function gnu_special in the cplus-dem.c file.
5
Can CVE-2025-66862 be exploited remotely?
Yes, CVE-2025-66862 can be exploited remotely via crafted PE files, leading to denial of service.