Описание
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
A NULL pointer dereference vulnerability in the elfutils library has been discovered. This vulnerability occurs within the handle_verdef() function in the readelf.c source file. A NULL pointer dereference typically happens when a program attempts to access memory using a pointer that is not pointing anywhere (i.e., it's NULL), leading to a crash or potentially exploitable behavior.
Отчет
This incident was classified as a standard bug rather than a security concern. Crashes in standalone utilities triggered by untrusted inputs typically aren't regarded as security issues since they don't lead to privilege escalation. It's important to highlight that unless eu-readelf is instrumented with AddressSanitizer, no actual crash occurs; instead, eu-readelf simply prints a random global string.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | elfutils | Out of support scope | ||
| Red Hat Enterprise Linux 7 | elfutils | Out of support scope | ||
| Red Hat Enterprise Linux 8 | elfutils | Fix deferred | ||
| Red Hat Enterprise Linux 8 | gcc-toolset-11-elfutils | Will not fix | ||
| Red Hat Enterprise Linux 9 | elfutils | Fix deferred | ||
| Red Hat Virtualization 4 | elfutils | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
4 Medium
CVSS3
Связанные уязвимости
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
elfutils v0.189 was discovered to contain a NULL pointer dereference v ...
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
EPSS
4 Medium
CVSS3