CVE-2025-66863: High severity GNU binutils vulnerability
Published Dec 29, 2025
·Updated
An issue was discovered in function ddiscriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
Affected Software
2 affected components
GNU binutils
GNU binutils=2.26
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66863?
CVE-2025-66863 has a medium severity rating due to its potential for denial of service attacks.
2
How do I fix CVE-2025-66863?
To mitigate CVE-2025-66863, update to the latest version of BinUtils where the vulnerability has been patched.
3
What causes the CVE-2025-66863 vulnerability?
CVE-2025-66863 is caused by improper handling of crafted PE files in the d_discriminator function within cp-demangle.c.
4
Is CVE-2025-66863 exploitable remotely?
CVE-2025-66863 can be exploited remotely if an attacker can trigger the vulnerability through the use of specially crafted PE files.
5
Who is affected by CVE-2025-66863?
CVE-2025-66863 affects users of BinUtils 2.26 and versions prior if they process untrusted PE files.