PT-2026-1781 · Lief · Lief

Oneafter

·

Published

2026-01-10

·

Updated

2026-04-30

·

CVE-2025-15504

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lief-project LIEF versions up to 0.17.1
Description A security flaw exists in LIEF, specifically within the ELF Binary Parser component. The issue resides in the Parser::parse binary function located in the file src/ELF/Parser.tcc. This manipulation can lead to a null pointer dereference. The attack requires local access. An exploit for this issue has been publicly released.
Recommendations Upgrade to version 0.17.2 or later to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-15504
GHSA-MJJP-XJFG-97WG

Affected Products

Lief