PT-2025-6906 · Gnu+5 · Gnu Elfutils+5
Wenjusun
·
Published
2025-02-16
·
Updated
2026-02-13
·
CVE-2025-1377
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
GNU elfutils version 0.192
Description:
A problem has been found in GNU elfutils that affects the
gelf getsymshndx function of the file strip.c in the eu-strip component. This issue leads to denial of service and must be approached locally. The exploit has been disclosed and may be used.Recommendations:
To fix this issue, apply a patch with the identifier fbf1df9ca286de3323ae541973b08449f8d03aba to GNU elfutils version 0.192. As a temporary workaround, consider disabling the
gelf getsymshndx function until a patch is available.Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Gnu Elfutils
Linuxmint
Red Os
Suse
Ubuntu