CVE-2016-10255: Buffer Overflow
Last updated 25 August 2025
Other sources
The libelfsetrawdatawrlock function in elfgetdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) shoff or (2) shsize ELF header value, which triggers a memory allocation failure.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1 - Upgrade
Upgrade
elfutilsto a version that resolves this vulnerability.Fixed in 0.168
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10255?
CVE-2016-10255 is classified as a moderate severity vulnerability that can lead to denial of service.
How do I fix CVE-2016-10255?
To address CVE-2016-10255, update elfutils to version 0.183-1 or later.
Who is affected by CVE-2016-10255?
Users of elfutils versions prior to 0.168 are vulnerable to CVE-2016-10255.
What is the impact of CVE-2016-10255?
CVE-2016-10255 can cause a denial of service by triggering a crash through crafted ELF header values.
Is CVE-2016-10255 a remote vulnerability?
Yes, CVE-2016-10255 can be exploited by remote attackers.