This update for elfutils fixes the following issues:
* Fixing build/testsuite for more recent glibc and kernels.
* Fixing denial of service and general buffer overflow errors (bsc#1237236,
bsc#1237240, bsc#1237241, bsc#1237242):
* CVE-2025-1376: Fixed denial of service in function elf_strptr in the library
/libelf/elf_strptr.c of the component eu-strip
* CVE-2025-1377: Fixed denial of service in function gelf_getsymshndx of the
file strip.c of the component eu-strip
* CVE-2025-1372: Fixed buffer overflow in function
dump_data_section/print_string_section of the file readelf.c of the
component eu-readelf
* CVE-2025-1352: Fixed SEGV (illegal read access) in function
__libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf
* Fixing testsuite race conditions in run-debuginfod-find.sh.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-4092=1
* SUSE Manager Proxy 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-4092=1
* SUSE Manager Retail Branch Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-
Server-4.3-LTS-2025-4092=1
* SUSE Manager Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-4092=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-4092=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-4092=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-4092=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-4092=1
* SUSE Linux Enterprise Micro for Rancher...
Read the Full Advisory* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* libelf1-0.185-150400.5.8.3
* libasm-devel-0.185-150400.5.8.3
* elfutils-debuginfod-0.185-150400.5.8.2
* elfutils-debuginfod-debugsource-0.185-150400.5.8.2
* libdw-devel-0.185-150400.5.8.3
* libdebuginfod1-debuginfo-0.185-150400.5.8.2
* elfutils-0.185-150400.5.8.3
* libasm1-0.185-150400.5.8.3
* libdebuginfod1-0.185-150400.5.8.2
* libelf-devel-0.185-150400.5.8.3
* libelf1-debuginfo-0.185-150400.5.8.3
* debuginfod-client-0.185-150400.5.8.2
* elfutils-debuginfod-debuginfo-0.185-150400.5.8.2
* libasm1-debuginfo-0.185-150400.5.8.3
* debuginfod-client-debuginfo-0.185-150400.5.8.2
* elfutils-debugsource-0.185-150400.5.8.3
* libdw1-0.185-150400.5.8.3
* libdw1-debuginfo-0.185-150400.5.8.3
* libdebuginfod-devel-0.185-150400.5.8.2
* elfutils-debuginfo-0.185-150400.5.8.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* elfutils-lang-0.185-150400.5.8.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
*...
Read the Full Advisory* bsc#1237236
* bsc#1237240
* bsc#1237241
* bsc#1237242
## References:
* https://www.suse.com/security/cve/CVE-2025-1352.html
* https://www.suse.com/security/cve/CVE-2025-1372.html
* https://www.suse.com/security/cve/CVE-2025-1376.html
* https://www.suse.com/security/cve/CVE-2025-1377.html
* https://bugzilla.suse.com/show_bug.cgi?id=1237236
* https://bugzilla.suse.com/show_bug.cgi?id=1237240
* https://bugzilla.suse.com/show_bug.cgi?id=1237241
* https://bugzilla.suse.com/show_bug.cgi?id=1237242
Get the latest Linux and open source security news straight to your inbox.