NULL pointer dereference in elfutils - CVE-2025-1371
Published: March 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the handle_dynamic_symtab() function in readelf.c. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Ubuntu
openEuler
elfutils (Ubuntu package)
elfutils-default-yama-scope
elfutils-libs
elfutils-libelf-devel
elfutils-libelf
elfutils-help
elfutils-extra
elfutils-devel
elfutils-debugsource
elfutils-debuginfod-client-devel
elfutils-debuginfod-client
elfutils-debuginfod
elfutils-debuginfo
elfutils
How to mitigate CVE-2025-1371
elfutils-default-yama-scope - update to 0.190-8
elfutils-libs - update to 0.190-8
elfutils-libelf-devel - update to 0.190-8
elfutils-libelf - update to 0.190-8
elfutils-help - update to 0.190-8
elfutils-extra - update to 0.190-8
elfutils-devel - update to 0.190-8
elfutils-debugsource - update to 0.190-8
elfutils-debuginfod-client-devel - update to 0.190-8
elfutils-debuginfod-client - update to 0.190-8
elfutils-debuginfod - update to 0.190-8
elfutils-debuginfo - update to 0.190-8
elfutils - update to 0.190-8