CVE-2025-1371

Name
CVE-2025-1371
Description
A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://sourceware.org/bugzilla/attachment.cgi?id=15926
issue-tracking https://sourceware.org/bugzilla/show_bug.cgi?id=32655
issue-tracking https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2
signature https://vuldb.com/?ctiid.295978
vdb-entry https://vuldb.com/?id.295978
third-party-advisory https://vuldb.com/?submit.496484
product https://www.gnu.org/

Match rules

CPE URI Source package Min version Max version
elfutils == 0.192 == 0.192

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
elfutils edge-main 0.192-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable