CVE-2025-66862

NameCVE-2025-66862
DescriptionA buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
binutils (PTS)bullseye2.35.2-2vulnerable
bookworm2.40-2vulnerable
trixie2.44-3vulnerable
forky, sid2.45.50.20251209-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
binutilssource(unstable)(unfixed)unimportant

Notes

binutils not covered by security support and most certainly bogus since they
were assigned for a very old binutils release

Search for package or bug name: Reporting problems