PT-2025-6906 · Gnu+5 · Gnu Elfutils+5

Wenjusun

·

Published

2025-02-16

·

Updated

2026-02-13

·

CVE-2025-1377

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GNU elfutils version 0.192
Description: A problem has been found in GNU elfutils that affects the gelf getsymshndx function of the file strip.c in the eu-strip component. This issue leads to denial of service and must be approached locally. The exploit has been disclosed and may be used.
Recommendations: To fix this issue, apply a patch with the identifier fbf1df9ca286de3323ae541973b08449f8d03aba to GNU elfutils version 0.192. As a temporary workaround, consider disabling the gelf getsymshndx function until a patch is available.

Exploit

Fix

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-56980
CVE-2025-1377
ECHO-A210-10F4-5953
MGASA-2025-0119
OESA-2025-1177
OESA-2025-1178
OESA-2025-1179
OESA-2025-1180
OESA-2025-1181
SUSE-RU-2025:4092-1
SUSE-SU-2025:4092-1
USN-7369-1

Affected Products

Debian
Gnu Elfutils
Linuxmint
Red Os
Suse
Ubuntu