
Our CTI team identified a lot of activities targeting GNU elfutils (CVE-2025-1377) https://vuldb.com/?ctiid.295985
Post summary
CTI team reports detection of multiple exploitation activities against CVE-2025-1377 in GNU elfutils.
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.
Priority
LOW
Exploitation
ACTIVE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

Our CTI team identified a lot of activities targeting GNU elfutils (CVE-2025-1377) https://vuldb.com/?ctiid.295985
Post summary
CTI team reports detection of multiple exploitation activities against CVE-2025-1377 in GNU elfutils.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | elfutils_project | elfutils | 0.192 | - | - |