HomeDefectsLIN1023-3725
Not to be fixed

LIN1023-3725 : Security Advisory - elfutils - CVE-2024-25260

Created: Feb 20, 2024    Updated: May 22, 2026
Resolved Date: May 13, 2026
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

========Wind River Notice========
This CVE is assessed as not a security issue based on the following:

Upstream (elfutils maintainer): Crashes in standalone CLI utilities on untrusted input do not constitute security vulnerabilities as they do not cause privilege escalation. See
elfutils SECURITY policy (https://sourceware.org/cgit/elfutils/tree/SECURITY).
Red Hat: Closed as "not a security issue" (reference (https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-25260)).
Debian: Rated as "unimportant" — normal bug, not a security issue (reference (https://security-tracker.debian.org/tracker/CVE-2024-25260)).