HomeGnuCVE-2025-69644

CVE-2025-69644

MEDIUM
5.0CVSS
Published: 2026-03-06
Updated: 2026-03-10
AI Analysis

Description

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Attack Vector
local
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-400

Metadata

Primary Vendor
GNU
Published
3/6/2026
Last Modified
3/10/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

gnu : binutils

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-69644 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com