Bugzilla – Bug 1220199
VUL-0: CVE-2024-25260: elfutils: global-buffer-overflow exists in the function ebl_machine_flag_name in eblmachineflagname.c
Last modified: 2024-03-18 14:09:50 UTC
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25260 https://sourceware.org/bugzilla/show_bug.cgi?id=31058 https://sourceware.org/elfutils/ https://www.cve.org/CVERecord?id=CVE-2024-25260 https://github.com/schsiung/fuzzer_issues/issues/1 https://bugzilla.redhat.com/show_bug.cgi?id=2265194 Patch: https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=373f5212677235fc3ca6068b887111554790f944
Tracking as affected: - SUSE:ALP:Source:Standard:1.0/elfutils - openSUSE:Factory/elfutils