CVE-2025-1352 is a critical memory corruption vulnerability in GNU elfutils versions up to 0.192, specifically affecting the eu-readelf component's libdw_alloc.c library. This flaw, rated 7.5 HIGH, can be triggered remotely through manipulation of the 'w' argument, potentially leading to high impact on confidentiality, integrity, and availability. While the attack complexity is high and exploitation is considered difficult, a public patch (2636426a091bd6c6f7f02e49ab20d4cdc6bfc753) is available, and the exploit has been publicly disclosed, though no active exploitation or widespread community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.192CPE matchmatch criteria | cpe:2.3:a:elfutils_project:elfutils:0.192:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.