5.3
CVSSv3

CVE-2025-1372

CVSSv4: 4.8 | CVSSv3: 5.3 | CVSSv2: 4.3 | VMScore: 580 | EPSS: 0.00022 | KEV: Not Included
Published: 17/02/2025 Updated: 17/02/2025

Vulnerability Summary

Local Buffer Overflow Vulnerability in GNU elfutils 0.192 Readelf Component

A critical vulnerability has been discovered in GNU elfutils version 0.192. The issue exists in the dump_data_section/print_string_section function within the readelf.c file of the eu-readelf component. By manipulating the z/x argument, an attacker can trigger a buffer overflow vulnerability. This security flaw requires a local attack approach. The vulnerability details have been made public, and an exploit may potentially be used. The patch for addressing this security issue is identified by the commit hash 73db9d2021cab9e23fd734b0a76a612d52a6f1db. Users are strongly advised to apply the available patch to mitigate the risk.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu elfutils