CVE-2017-7610: Medium severity Elfutils Project Elfutils vulnerability
Last updated 25 August 2025
Other sources
The checkgroup function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7610?
CVE-2017-7610 has been categorized as a moderate severity vulnerability that can lead to denial of service.
How do I fix CVE-2017-7610?
To fix CVE-2017-7610, update the elfutils package to versions newer than 0.168, specifically 0.183-1, 0.188-2.1, or 0.191-2.
What type of attack does CVE-2017-7610 involve?
CVE-2017-7610 involves a remote attacker exploiting a crafted ELF file to trigger a heap-based buffer over-read and cause an application crash.
Which systems are affected by CVE-2017-7610?
CVE-2017-7610 affects elfutils version 0.168 running on systems such as Debian 8.0 and Ubuntu 14.04 or 16.04.
What is the impact of CVE-2017-7610?
The impact of CVE-2017-7610 is a denial of service that results in an application crash when vulnerable systems process a malicious ELF file.