First published: Tue Jul 18 2023(Updated: )
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/elfutils | <=0.183-1 | 0.188-2.1 0.192-4 |
CentOS Elfutils | =0.183 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33294 has been classified as a denial of service vulnerability due to an infinite loop in the elfutils library.
To fix CVE-2021-33294, upgrade elfutils to version 0.188-2.1 or later, or 0.192-4 or later.
CVE-2021-33294 affects elfutils version 0.183 and older versions prior to 0.188-2.1 and 0.192-4.
CVE-2021-33294 can be exploited to cause a denial of service through crafted ELF files leading to an infinite loop.
Yes, CVE-2021-33294 is publicly documented and reported in the elfutils project communications.