CVE-2025-1352Disclosure(elfutils_project / elfutils)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch elfutils_project elfutils systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elfutils

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
elfutils

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Remote-triggerable memory corruption in elfutils eu-readelf (__libdw_thread_tail) (CVE-2025-1352) GNU elfutils 0.192 is vulnerable to memory corruption in the __libdw_thread_tail routine within libdw_alloc.c, reachable via the eu-readelf component when processing crafted inputs. The underlying issue is a memory-safety flaw (heap memory corruption) consistent with improper bounds handling/unsafe pointer arithmetic in the thread-tail allocation logic. An attacker can potentially trigger this remotely by feeding eu-readelf a malicious ELF file or otherwise manipulating the argument w passed into the vulnerable code path, though exploitation is considered difficult and high-complexity. Successful exploitation can lead to process crashes (DoS) and, in worst cases, arbitrary code execution in the context of the user running eu-readelf. 👉 Affected: elfutils 0.192 | Upgrade to a build including commit 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753

    Post summary

    The text announces CVE‑2025‑1352, details the vulnerability and its impact, and provides a specific patch reference.

    0000069
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelfutils_projectelfutils0.192--

Explore more