Where
-Infinity
0

Vendor Risk Score

See how elfutils compares to other vendors in security performance

View Risk Score →
Severity
4
EPSS
0.04%
Null Pointer Dereference
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handleverdef() function at readelf.c.

1 / 2
Source: NVD
First published (updated )
Severity
1

Elfutils is vulnerable to a heap-based buffer over-read in the libdw/dwarfgetaranges.c:dwarfgetaranges() function. An attacker could exploit this to cause a crash in the eu-addr2line command via a crafted file.

Upstream Bug:

https://sourceware.org/bugzilla/showbug.cgi?id=23541

Upstream Patch:

https://sourceware.org/git/?p=elfutils.git;a=commit;h=29e31978ba51c1051743a503ee325b5ebc03d7e9

First published (updated )
Severity
1

Elfutils through version 0.173 is vulnerable to a heap-based buffer over-read due to incorrect checks for the end of attribute lists in the libdw/dwarfgetabbrev.c:libdwgetabbrev() and libdw/dwarfhasattr.c:dwarfhasattr() functions. An attacker could exploit this to cause a crash via a crafted ELF.

Upstream Bug:

https://sourceware.org/bugzilla/showbug.cgi?id=23529

Upstream Patch:

https://sourceware.org/git/?p=elfutils.git;a=patch;h=6983e59b727458a6c64d9659c85f08218bc4fcda

First published (updated )
Severity
1

Elfutils through version 0.173 is vulnerable to a double-free in the libelf/elfend.c:elfend() function due to the decompression of section data multiple times.. An attacker could exploit this to cause a crash or possibly have unspecified other impact via a crafted ELF.

Upstream Bug:

https://sourceware.org/bugzilla/showbug.cgi?id=23528

Upstream Patch:

https://sourceware.org/git/?p=elfutils.git;a=patch;h=56b18521fb8d46d40fc090c0de9d11a08bc982fa

First published (updated )
Severity
1

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32xlatetom in elf32xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because eblcorenote does not reject malformed core file notes.

References: https://sourceware.org/bugzilla/showbug.cgi?id=24089 https://sourceware.org/ml/elfutils-devel/2019-q1/msg00049.html

First published (updated )
Severity
1

In elfutils 0.175, there is a buffer over-read in the eblobjectnote function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file.

References: https://sourceware.org/bugzilla/showbug.cgi?id=24075 https://sourceware.org/bugzilla/showbug.cgi?id=24081

Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=commit;h=012018907ca05eb0ab51d424a596ef38fc87cae1 https://sourceware.org/git/?p=elfutils.git;a=commit;h=cd7ded3df43f655af945c869976401a602e46fcd

First published (updated )
Severity
1

A flaw was found in elfutils 0.174. A Divide-by-zero vulnerabilities in the function arlibaddsymbols() in arlib.c allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero shentsize is mishandled.

References: https://sourceware.org/bugzilla/showbug.cgi?id=23786 https://sourceware.org/ml/elfutils-devel/2018-q4/msg00055.html

Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=commit;h=2b16a9be69939822dcafe075413468daac98b327

First published (updated )
Severity
1

In elfutils 0.175, a negative-sized memcpy is attempted in elfcvtnote in libelf/notexlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).

Reference: https://sourceware.org/bugzilla/showbug.cgi?id=24084

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203