ALAS2-2023-2197

Related Vulnerabilities: CVE-2021-33294  

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. (CVE-2021-33294)

ALAS2-2023-2197


Amazon Linux 2 Security Advisory: ALAS-2023-2197
Advisory Release Date: 2023-08-03 18:10 Pacific
Advisory Updated Date: 2023-08-08 22:02 Pacific
Severity: Low

Issue Overview:

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. (CVE-2021-33294)


Affected Packages:

elfutils


Issue Correction:
Run yum update elfutils to update your system.

New Packages:
aarch64:
    elfutils-0.176-2.amzn2.0.1.aarch64
    elfutils-libs-0.176-2.amzn2.0.1.aarch64
    elfutils-devel-0.176-2.amzn2.0.1.aarch64
    elfutils-devel-static-0.176-2.amzn2.0.1.aarch64
    elfutils-libelf-0.176-2.amzn2.0.1.aarch64
    elfutils-libelf-devel-0.176-2.amzn2.0.1.aarch64
    elfutils-libelf-devel-static-0.176-2.amzn2.0.1.aarch64
    elfutils-debuginfo-0.176-2.amzn2.0.1.aarch64

i686:
    elfutils-0.176-2.amzn2.0.1.i686
    elfutils-libs-0.176-2.amzn2.0.1.i686
    elfutils-devel-0.176-2.amzn2.0.1.i686
    elfutils-devel-static-0.176-2.amzn2.0.1.i686
    elfutils-libelf-0.176-2.amzn2.0.1.i686
    elfutils-libelf-devel-0.176-2.amzn2.0.1.i686
    elfutils-libelf-devel-static-0.176-2.amzn2.0.1.i686
    elfutils-debuginfo-0.176-2.amzn2.0.1.i686

noarch:
    elfutils-default-yama-scope-0.176-2.amzn2.0.1.noarch

src:
    elfutils-0.176-2.amzn2.0.1.src

x86_64:
    elfutils-0.176-2.amzn2.0.1.x86_64
    elfutils-libs-0.176-2.amzn2.0.1.x86_64
    elfutils-devel-0.176-2.amzn2.0.1.x86_64
    elfutils-devel-static-0.176-2.amzn2.0.1.x86_64
    elfutils-libelf-0.176-2.amzn2.0.1.x86_64
    elfutils-libelf-devel-0.176-2.amzn2.0.1.x86_64
    elfutils-libelf-devel-static-0.176-2.amzn2.0.1.x86_64
    elfutils-debuginfo-0.176-2.amzn2.0.1.x86_64