A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.
References
| Link | Resource |
|---|---|
| https://sourceware.org/bugzilla/attachment.cgi?id=15941 | Exploit |
| https://sourceware.org/bugzilla/show_bug.cgi?id=32673 | Exploit Issue Tracking |
| https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.295985 | Permissions Required VDB Entry |
| https://vuldb.com/?id.295985 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.497539 | Third Party Advisory VDB Entry |
| https://www.gnu.org/ | Product |
Configurations
History
04 Nov 2025, 20:26
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:elfutils_project:elfutils:0.192:*:*:*:*:*:*:* | |
| References | () https://sourceware.org/bugzilla/attachment.cgi?id=15941 - Exploit | |
| References | () https://sourceware.org/bugzilla/show_bug.cgi?id=32673 - Exploit, Issue Tracking | |
| References | () https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.295985 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.295985 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.497539 - Third Party Advisory, VDB Entry | |
| References | () https://www.gnu.org/ - Product | |
| First Time |
Elfutils Project
Elfutils Project elfutils |
17 Feb 2025, 05:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-17 05:15
Updated : 2025-11-04 20:26
NVD link : CVE-2025-1377
Mitre link : CVE-2025-1377
CVE.ORG link : CVE-2025-1377
JSON object : View
Products Affected
elfutils_project
- elfutils
CWE
CWE-404
Improper Resource Shutdown or Release
