CVE-2025-69644: Medium severity GNU binutils vulnerability
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69644?
CVE-2025-69644 is classified as a denial-of-service vulnerability.
How do I fix CVE-2025-69644?
To mitigate CVE-2025-69644, you should upgrade to Binutils version 2.46 or later.
What software is affected by CVE-2025-69644?
CVE-2025-69644 affects GNU Binutils versions prior to 2.46.
What kind of attack is enabled by CVE-2025-69644?
CVE-2025-69644 can lead to an unbounded loop in objdump, resulting in a denial-of-service condition.
How was CVE-2025-69644 discovered?
CVE-2025-69644 was discovered in the Binutils software while analyzing the handling of malformed debug information.