VYPR

readelf

by GNU

CVEs (8)

  • CVE-2022-45703HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

  • CVE-2022-44840HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.

  • CVE-2017-15996HigOct 29, 2017
    risk 0.51cvss 7.8epss 0.02

    elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized…

  • CVE-2025-69647MedMar 9, 2026
    risk 0.40cvss 6.2epss 0.00

    GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress,…

  • CVE-2025-69652MedMar 6, 2026
    risk 0.40cvss 6.2epss 0.00

    GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate…

  • CVE-2026-6844MedApr 22, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead…

  • CVE-2022-35206MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.

  • CVE-2022-35205MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.