Advisories ยป MGASA-2025-0119

Updated elfutils packages fix security vulnerabilities

Publication date: 31 Mar 2025
Modification date: 31 Mar 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-25260 , CVE-2025-1372 , CVE-2025-1377

Description

elfutils v0.189 was discovered to contain a NULL pointer dereference via
the handle_verdef() function at readelf.c. (CVE-2024-25260)
GNU elfutils eu-readelf readelf.c print_string_section buffer overflow.
(CVE-2025-1372)
GNU elfutils eu-strip strip.c gelf_getsymshndx denial of service.
(CVE-2025-1377)
                

References

SRPMS

9/core