CVE-2025-66865: High severity GNU binutils vulnerability
Published Dec 29, 2025
·Updated
An issue was discovered in function dprintcompinner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
Affected Software
2 affected components
GNU binutils
GNU binutils=2.26
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66865?
CVE-2025-66865 has been identified as a denial of service vulnerability.
2
How do I fix CVE-2025-66865?
To fix CVE-2025-66865, you should update to a later version of GNU BinUtils that has addressed this issue.
3
Which versions of BinUtils are affected by CVE-2025-66865?
CVE-2025-66865 affects GNU BinUtils version 2.26 and earlier versions.
4
What kind of attack does CVE-2025-66865 enable?
CVE-2025-66865 allows attackers to cause a denial of service through the use of crafted PE files.
5
Where is the vulnerability CVE-2025-66865 located in the BinUtils source code?
CVE-2025-66865 is located in the function d_print_comp_inner in the file cp-demangle.c.