Denial of Service Vulnerability in BinUtils by The GNU Project
CVE-2025-66864

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 December 2025

What is CVE-2025-66864?

A denial of service vulnerability exists in BinUtils 2.26 that can be exploited by attackers using specially crafted Portable Executable (PE) files. This flaw, found in the d_print_comp_inner function within cp-demangle.c, allows maliciously crafted files to disrupt service, impacting the functionality of the affected software. Users are advised to upgrade to the latest version and apply necessary security measures to safeguard against this exploit.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.