CVE-2024-25260
published 2024-02-20CVE-2024-25260: elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
PriorityP413medium4CVSS 3.1
AVLACLPRNUINSUCNINAL
EPSS
0.31%
23.0th percentile
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | elfutils | — | — |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.186-1ubuntu0.1 | 0.186-1ubuntu0.1 |
| elfutils_project | elfutils | >= 0 < 0.190-1.1ubuntu0.1 | 0.190-1.1ubuntu0.1 |
| msrc | azl3_elfutils_0.189-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_elfutils_0.189-6_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.14.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2025-03-24·CVSS 4.0
CVE-2025-1365 [MEDIUM] elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: Several security issues were fixed in elfutils.
It was discovered that readelf from elfutils could be made to read out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service. This issue only affected Ubuntu 24.04
LTS. (CVE-2024-25260)
It was discovered that readelf from elfutils could be made to write out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-1365)
It was discovered that readelf f
Red Hat
elfutils: global-buffer-overflow exists in the function ebl_machine_flag_name in eblmachineflagname.c
vendor_redhat·2024-02-20·CVSS 4.0
CVE-2024-25260 [MEDIUM] CWE-119 elfutils: global-buffer-overflow exists in the function ebl_machine_flag_name in eblmachineflagname.c
elfutils: global-buffer-overflow exists in the function ebl_machine_flag_name in eblmachineflagname.c
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it's NULL), leading to a crash or potentially exploitable behavior.
Statement: This incident was classified as a standard bug rather than a security concern. Crashes in standalone utilities triggered by untrusted inputs typically aren't regarded as security issu
Microsoft
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
vendor_msrc·2024-02-13·CVSS 4.0
CVE-2024-25260 [MEDIUM] CWE-476 elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2024-25260: elfutils - elfutils v0.189 was discovered to contain a NULL pointer dereference via the han...
vendor_debian·2024·CVSS 4.0
CVE-2024-25260 [MEDIUM] CVE-2024-25260: elfutils - elfutils v0.189 was discovered to contain a NULL pointer dereference via the han...
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
elfutils vulnerabilities
osv·2025-03-24·CVSS 4.0
CVE-2024-25260 [MEDIUM] elfutils vulnerabilities
elfutils vulnerabilities
It was discovered that readelf from elfutils could be made to read out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service. This issue only affected Ubuntu 24.04
LTS. (CVE-2024-25260)
It was discovered that readelf from elfutils could be made to write out of
bounds. If a user or automated system were tricked into running readelf
on a specially crafted file, an attacker could cause readelf to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-1365)
It was discovered that readelf from elfutils could be made to dereference
invalid memory. If a us
GHSA
GHSA-c5x5-p58w-fxgh: elfutils v0
ghsa_unreviewed·2024-02-20
CVE-2024-25260 [MEDIUM] CWE-476 GHSA-c5x5-p58w-fxgh: elfutils v0
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
OSV
CVE-2024-25260: elfutils v0
osv·2024-02-20·CVSS 4.0
CVE-2024-25260 [MEDIUM] CVE-2024-25260: elfutils v0
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-20
Published