CVE-2025-69644

Published: March 11, 2026Last modified: March 28, 2026

Description

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

Severity score breakdown

ParameterValue
Base score5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbinutilsUnknown (2.39-r2)
25 LTSbinutilsFixed (2.45.1-r1)
StreambinutilsFixed (2.45.1-r3)
Hardened Containers23 LTSbinutilsUnknown (2.39-r2)
25 LTSbinutilsFixed (2.45.1-r1)
StreambinutilsFixed (2.45.1-r3)

References

ON THIS PAGE