elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade elfutils | Jul 30, 2024 | Apr 9, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/elfutils. | Oct 30, 2017 | Apr 9, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 4, 2017 |
| Suse | — | Upgrade libasm1-32bitUpgrade libelf1Upgrade elfutilsUpgrade libdw1Upgrade libebl-pluginsUpgrade libelf-devel-32bitUpgrade libasm-develUpgrade libasm1Upgrade libdw1-32bitUpgrade libebl-plugins-32bitUpgrade libelf-develUpgrade libebl-develUpgrade elfutils-langUpgrade libelf1-32bitUpgrade libdw-devel | Jun 20, 2019 | Apr 9, 2017 |
| Ubuntu | — | Upgrade libelf1Upgrade libasm1Upgrade elfutilsUpgrade libdw1 | Jun 12, 2018 | Apr 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub