First published: Mon Mar 24 2025(Updated: )
It was discovered that readelf from elfutils could be made to read out of bounds. If a user or automated system were tricked into running readelf on a specially crafted file, an attacker could cause readelf to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-25260) It was discovered that readelf from elfutils could be made to write out of bounds. If a user or automated system were tricked into running readelf on a specially crafted file, an attacker could cause readelf to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-1365) It was discovered that readelf from elfutils could be made to dereference invalid memory. If a user or automated system were tricked into running readelf on a specially crafted file, an attacker could cause readelf to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-1371) It was discovered that readelf from elfutils could be made to dereference invalid memory. If a user or automated system were tricked into running readelf on a specially crafted file, an attacker could cause readelf to crash, resulting in a denial of service. (CVE-2025-1372) It was discovered that strip from elfutils could be made to dereference invalid memory. If a user or automated system were tricked into running strip on a specially crafted file, an attacker could cause strip to crash, resulting in a denial of service. (CVE-2025-1377)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/elfutils | <0.191-2ubuntu0.1 | 0.191-2ubuntu0.1 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/elfutils | <0.190-1.1ubuntu0.1 | 0.190-1.1ubuntu0.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/elfutils | <0.186-1ubuntu0.1 | 0.186-1ubuntu0.1 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-7369-1 is categorized as a denial of service vulnerability that can crash the readelf utility.
To fix USN-7369-1, update the elfutils package to version 0.191-2ubuntu0.1 or later for Ubuntu 24.10, 0.190-1.1ubuntu0.1 or later for Ubuntu 24.04, or 0.186-1ubuntu0.1 or later for Ubuntu 22.04.
The impact of USN-7369-1 allows an attacker to cause a denial of service by tricking the user into running readelf on a specially crafted file.
USN-7369-1 affects Ubuntu operating systems including versions 22.04, 24.04, and 24.10 that use the elfutils package.
Yes, USN-7369-1 can be exploited if a user or automated system is deceived into executing the vulnerable readelf utility on a malicious file.