CVE-2025-69646

Source
https://cve.org/CVERecord?id=CVE-2025-69646
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69646.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69646
Downstream
Published
2026-03-06T18:16:16.500Z
Modified
2026-03-14T01:54:19.502089Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debugrnglists data. A logic error in the handling of the debugrnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69646.json"