elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. ========Wind River Notice======== This CVE is assessed as not a security issue based on the following: Upstream (elfutils maintainer): Crashes in standalone CLI utilities on untrusted input do not constitute security vulnerabilities as they do not cause privilege escalation. See elfutils SECURITY policy (https://sourceware.org/cgit/elfutils/tree/SECURITY). Red Hat: Closed as "not a security issue" (reference (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-25260)). Debian: Rated as "unimportant" — normal bug, not a security issue (reference (https://security-tracker.debian.org/tracker/CVE-2024-25260)).