CVE-2017-7612: Medium severity Elfutils Project Elfutils vulnerability
Last updated 25 August 2025
Other sources
The checksysvhash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7612?
CVE-2017-7612 has a severity rating that indicates it can cause a denial of service due to a heap-based buffer over-read.
How do I fix CVE-2017-7612?
To fix CVE-2017-7612, upgrade to versions of elfutils later than 0.168, specifically to 0.183-1, 0.188-2.1, or 0.191-2.
What software is affected by CVE-2017-7612?
CVE-2017-7612 affects elfutils version 0.168 and is prevalent on Debian 8.0 and Ubuntu 14.04 and 16.04.
Can CVE-2017-7612 be exploited remotely?
Yes, CVE-2017-7612 can be exploited by remote attackers through a specially crafted ELF file.
What are the consequences of CVE-2017-7612?
The main consequence of CVE-2017-7612 is an application crash, which results in denial of service.