VendorsGNUbinutils2.44
Vulnerabilities

GNU Binutils 2.44

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-1153
GNU Binutils format.c bfd_set_format memory corruption
Published 2025-02-10 · Modified
5.9EPSS 0.014
CVE-2025-3198
GNU Binutils objdump bucomm.c display_info memory leak
Published 2025-04-04 · Modified
5.5EPSS 0.003
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Published 2025-07-27 · Modified
5.5EPSS 0.002
CVE-2025-69645
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
Published 2026-03-06 · Analyzed
5.5EPSS 0.002
CVE-2025-69646
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Published 2026-03-06 · Analyzed
5.5EPSS 0.002
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Published 2025-07-27 · Analyzed
3.3EPSS 0.002