mirror of
https://git.yoctoproject.org/poky
synced 2026-07-29 22:17:46 +02:00
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). A local attacker can trigger the crash by supplying a malicious input file. (From OE-Core rev: ca101b2ff0b91630df25ee619c809e0621d41b21) Signed-off-by: Roland Kovacs <roland.kovacs@est.tech> [YC: The patch is referenced on the NVD page: https://nvd.nist.gov/vuln/detail/CVE-2025-69645 ] Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>