CVE-2017-7611: Medium severity Elfutils Project Elfutils vulnerability
Last updated 25 August 2025
Other sources
The checksymtabshndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7611?
CVE-2017-7611 is classified as a medium severity vulnerability that can lead to a denial of service.
How do I fix CVE-2017-7611?
To remediate CVE-2017-7611, upgrade to elfutils versions 0.183-1, 0.188-2.1, or 0.191-2.
What types of systems are affected by CVE-2017-7611?
CVE-2017-7611 affects systems running elfutils version 0.168 on Debian and Ubuntu distributions.
What kind of attack is possible with CVE-2017-7611?
CVE-2017-7611 allows remote attackers to exploit a crafted ELF file, leading to a heap-based buffer over-read and potential application crash.
Is CVE-2017-7611 related to specific software versions?
Yes, CVE-2017-7611 specifically affects elfutils version 0.168 and can compromise systems using this version.