CVE-2017-7608: Medium severity Elfutils Project Elfutils vulnerability
Last updated 25 August 2025
Other sources
The eblobjectnotetypename function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7608?
CVE-2017-7608 is classified as a denial of service vulnerability that can lead to an application crash.
How do I fix CVE-2017-7608?
To remediate CVE-2017-7608, update elfutils to versions later than 0.168, specifically 0.183-1, 0.188-2.1, or 0.191-2.
Which software versions are affected by CVE-2017-7608?
CVE-2017-7608 affects elfutils version 0.168, primarily found in Debian 8.0 and Ubuntu 14.04 and 16.04.
What types of attacks can be executed using CVE-2017-7608?
An attacker can exploit CVE-2017-7608 to cause a denial of service through the use of a crafted ELF file.
Are there any known exploits for CVE-2017-7608?
Yes, CVE-2017-7608 has demonstrated vulnerabilities that allow for remote attackers to execute denial of service attacks.