CVE-2025-69645: Medium severity GNU binutils vulnerability
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offsetsize value being used inside bytegetlittleendian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.41-11
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69645?
CVE-2025-69645 has a severity rating that indicates it can lead to a denial-of-service condition.
How do I fix CVE-2025-69645?
To address CVE-2025-69645, you should update to the latest version of GNU Binutils that patches this vulnerability.
What is the impact of CVE-2025-69645?
CVE-2025-69645 can cause the objdump tool to abort unexpectedly when processing specific malformed DWARF debug information.
Who is affected by CVE-2025-69645?
Users of GNU Binutils that process binaries containing malformed DWARF debug information are affected by CVE-2025-69645.
When was CVE-2025-69645 disclosed?
The details for CVE-2025-69645 were disclosed as part of ongoing vulnerability tracking in GNU Binutils.