Bug 2445263 (CVE-2025-69644)

Summary: CVE-2025-69644 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: crizzo, gtanzill, jbuscemi, jmitchel, kshier, pbohmill, teagle
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in binutils. A local attacker can exploit a logic flaw in the handling of DWARF (Debugging With Attributed Record Formats) location list headers within the objdump utility. By supplying a crafted binary with malformed debug information, the attacker can cause objdump to enter an unbounded loop, leading to excessive resource consumption and a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2445268, 2445272, 2445281, 2445283, 2445287, 2445289, 2445275, 2445278    
Bug Blocks:    

Description OSIDB Bzimport 2026-03-06 18:01:34 UTC
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.