CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-69644: An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input

mediumCVSS 5CVE-2025-69644

CSIRTS triage

What
An unbounded loop in objdump's DWARF debug information parsing can cause denial of service when processing malformed binaries.
Who is affected
Systems using objdump (part of Binutils) to analyze untrusted or potentially malformed binary files.
Urgency
Medium; exploitation requires providing a crafted binary to the user, but can halt analysis tools.
Action
Update Binutils to version 2.46 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Binutils

Get an email when a new Binutils advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-69644

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-69644coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center