elfutils v0.189 was discovered to contain a NULL pointer dereference via
the handle_verdef() function at readelf.c. (CVE-2024-25260)
GNU elfutils eu-readelf readelf.c print_string_section buffer overflow.
(CVE-2025-1372)
GNU elfutils eu-strip strip.c gelf_getsymshndx denial of service.
(CVE-2025-1377)
- https://bugs.mageia.org/show_bug.cgi?id=34134
- https://ubuntu.com/security/notices/USN-7369-1
- https://www.cve.org/CVERecord?id=CVE-2024-25260
- https://www.cve.org/CVERecord?id=CVE-2025-1372
- https://www.cve.org/CVERecord?id=CVE-2025-1377
- 9/core/elfutils-0.189-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.