CVE-2025-1376
NixOS vulnerability analysis and mitigation

Overview

A vulnerability was discovered in GNU elfutils version 0.192, specifically affecting the elfstrptr function in the library /libelf/elfstrptr.c of the eu-strip component. The issue was discovered on February 10, 2025, and was fixed on February 13, 2025. The vulnerability could lead to a segmentation fault when processing specially crafted input files with the --reloc-debug-sections-only option (Sourceware Bugzilla).

Technical details

The vulnerability occurs in the validatestr function when elfstrptr is called on a section with shsize already set but without any data. This could happen when a new section was created with elfnewscn but no data had been added yet. The issue manifests as an illegal read access at address 0x00000e000007, triggering a segmentation fault. The vulnerability has been assigned a CVSS v3.1 score of 2.5 (Low) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L (NVD).

Impact

The vulnerability leads to a denial of service condition through a segmentation fault. The impact is considered low as it requires local access and high attack complexity. According to the elfutils maintainers, this is not considered a security issue as the tools are typically run in short-lived, local, interactive, development contexts rather than remotely in production (Sourceware Bugzilla).

Mitigation and workarounds

The issue has been fixed in a patch (commit b16f441cca0a4841050e3215a9f120a6d8aea918) which adds a check to verify that strscn->rawdatabase is not NULL before accessing the data. Users are recommended to update to the patched version. Additionally, a previous patch that checks for ETREL file types before processing helps prevent this issue in some distributions (Sourceware Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management