CVE-2025-1365 - CVE House
Back to Database
Status published Medium CVE-2025-1365

GNU elfutils eu-readelf readelf.c process_symtab buffer overflow

Vulnerability Description

A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1365

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • rookie (VulDB User)

Affected Vendor

Affected Software

elfutils
Vulnerable Versions:
0.192

Timeline

Official Publish: February 16th, 2025
Last Modified: February 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)