Logo
vulnerabilityCVE-2025-1371
Name
CVE-2025-1371
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
elfutils
Exploitable

Vulnerability Ratings#


4.8
CVSSv4
3.3
CVSSv31
5.5
CVSSv31
1.7
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.193
Not Affected
buildroot
master
0.195
Not Affected
openwrt
openwrt-25.12
0.192-r1
Exploitable
yocto
kirkstone
0.186
Not Affected
yocto
master
0.194
Not Affected
yocto
scarthgap
0.191
Not Affected