CVE-2025-1352

Publication date 16 February 2025

Last updated 7 May 2025


Ubuntu priority

Cvss 3 Severity Score

5.0 · Medium

Score breakdown

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Read the notes from the security team

Why is this CVE low priority?

Only a crash in a command line tool.

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
elfutils 25.04 plucky
Vulnerable
24.10 oracular
Vulnerable
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Notes


fabian

The associated patch does not fix the issue as the reproducer still triggers the bug.


mdeslaur

per upstream elfutils developers, they do not consider this issue to be a security issue. This CVE may get rejected. This is only a crash in a command-line tool, marking as low.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
elfutils

Severity score breakdown

Parameter Value
Base score 5.0 · Medium
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L