{"id":"DEBIAN-CVE-2025-1371","details":"A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.","modified":"2026-09-01T20:05:41.103772191Z","published":"2025-02-17T03:15:09.400Z","upstream":["CVE-2025-1371"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-1371"}],"affected":[{"package":{"name":"elfutils","ecosystem":"Debian:12","purl":"pkg:deb/debian/elfutils?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.188-2.1","0.189-1","0.189-2","0.189-3","0.189-4","0.190-1","0.190-1.1","0.190-1.1~exp1","0.191-1","0.191-1~bpo12+1","0.191-2","0.192-1","0.192-2","0.192-3","0.192-4","0.192-4~bpo12+1","0.193-1","0.193-2","0.193-3","0.193-3~bpo13+1","0.194+20260315-1","0.194-1","0.194-2","0.194-3","0.194-4","0.195-1","0.195-1~bpo13+1","0.196-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-1371.json"}},{"package":{"name":"elfutils","ecosystem":"Debian:13","purl":"pkg:deb/debian/elfutils?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.192-4","0.193-1","0.193-2","0.193-3","0.193-3~bpo13+1","0.194+20260315-1","0.194-1","0.194-2","0.194-3","0.194-4","0.195-1","0.195-1~bpo13+1","0.196-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-1371.json"}},{"package":{"name":"elfutils","ecosystem":"Debian:14","purl":"pkg:deb/debian/elfutils?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.192-4","0.193-1","0.193-2","0.193-3","0.193-3~bpo13+1","0.194+20260315-1","0.194-1","0.194-2","0.194-3","0.194-4","0.195-1","0.195-1~bpo13+1","0.196-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-1371.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}