CVE-2025-1376

CVSS 3.1 Score 2.5 of 10 (low)

Details

Published Feb 17, 2025
CWE ID 404

Summary

CVE-2025-1376 is a recently disclosed vulnerability affecting the GNU elfutils 0.192 library. Specifically, the function elf_strptr in the /libelf/elf_strptr.c component of eu-strip is vulnerable. This issue results in a denial-of-service condition and can be exploited locally with a high level of complexity. The exploitation process is reportedly difficult, but a public exploit is available. To mitigate this risk, it is strongly advised to apply the patch with the commit ID b16f441cca0a4841050e3215a9f120a6d8aea918.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share