- Description
- A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.
- Source
- cna@vuldb.com
- NVD status
- Analyzed
- Products
- elfutils
CVSS 4.0
- Type
- Secondary
- Base score
- 2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- LOW
CVSS 3.1
- Type
- Primary
- Base score
- 4.7
- Impact score
- 3.6
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Secondary
- Base score
- 1
- Impact score
- 2.9
- Exploitability score
- 1.5
- Vector string
- AV:L/AC:H/Au:S/C:N/I:N/A:P
- cna@vuldb.com
- CWE-404
- Hype score
- Not currently trending
openSUSE pushes elfutils update for DoS and buffer overflow bugs in eu-strip (CVE-2025-1376, -1377). If you're on recent glibc/kernels, patch before someone fuzzes you for free. #Linux https://t.co/aNmdCwKuwB
@threatcluster
24 Nov 2025
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1376 Local Denial of Service Vulnerability in GNU elfutils 0.192 elf_strptr Function https://t.co/2UBr0lYjcY
@VulmonFeeds
17 Feb 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1376 A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the… https://t.co/RIvCejAlk9
@CVEnew
17 Feb 2025
603 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New post from https://t.co/uXvPWJy6tj (CVE-2025-1376 | GNU elfutils 0.192 eu-strip /libelf/elf_strptr.c elf_strptr denial of service (Bug 15940)) has been published on https://t.co/cyUuSbVnbk
@WolfgangSesin
16 Feb 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:elfutils_project:elfutils:0.192:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BEB56CB-980B-4BF5-9490-9AF507E841A6"
}
],
"operator": "OR"
}
]
}
]