CVE-2025-69646

Source
https://cve.org/CVERecord?id=CVE-2025-69646
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69646.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69646
Downstream
Published
2026-03-06T00:00:00Z
Modified
2026-07-15T01:49:16.741958597Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debugrnglists data. A logic error in the handling of the debugrnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69646.json"
}
References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
815d9a14cbbb3b81843f7566222c87fb22e7255d
Last affected
815d9a14cbbb3b81843f7566222c87fb22e7255d
Database specific
{
    "cpe": "cpe:2.3:a:gnu:binutils:2.44:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "2.44"
        },
        {
            "last_affected": "2.44"
        }
    ]
}

Affected versions

2.*
2.44
Other
binutils-2_44

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69646.json"