[ubuntu/noble-security] elfutils 0.190-1.1ubuntu0.1 (Accepted)

Fabian Toepfer fabian.toepfer at canonical.com
Mon Mar 24 19:32:43 UTC 2025


elfutils (0.190-1.1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: out-of-bounds read
    - debian/patches/CVE-2024-25260.patch: Fix arm_machine_flag_name
      version string.
    - CVE-2024-25260
  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2025-1365.patch: Use validate_str also to check
      dynamic symstr data.
    - CVE-2025-1365
  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2025-1371.patch: Handle NULL phdr in
      handle_dynamic_symtab.
    - CVE-2025-1371
  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2025-1372.patch: Skip trying to uncompress
      sections without a name.
    - CVE-2025-1372
  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2025-1377.patch: Verify symbol table is a real
      symbol table.
    - CVE-2025-1377

Date: 2025-03-17 16:24:36.999687+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
https://launchpad.net/ubuntu/+source/elfutils/0.190-1.1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list