CVE-2019-7664
MEDIUMelfutils 0.175 - Denial of Service via Negative-Sized memcpy in elf_cvt_note
Title source: llmDescription
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
References (3)
Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=24084
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2197
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3575
Scores
CVSS v3
5.5
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-787
Status
published
Products (15)
elfutils_project/elfutils
0.175
redhat/enterprise_linux
8.0
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_eus
8.1
redhat/enterprise_linux_eus
8.2
redhat/enterprise_linux_eus
8.4
redhat/enterprise_linux_eus
8.6
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_server_aus
8.2
redhat/enterprise_linux_server_aus
8.4
... and 5 more
Published
Feb 09, 2019
Tracked Since
Feb 18, 2026