
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15504 is a null pointer dereference vulnerability in the ELF Binary Parser component of lief-project LIEF (Library to Instrument Executable Formats). It affects all versions up to and including 0.17.1, specifically in the Parser::parse_binary function within src/ELF/Parser.tcc. The vulnerability was reported on December 10, 2025, and publicly disclosed on January 10, 2026, with a fix released in version 0.17.2. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 1.9 (Low) under CVSS v4.0 per the CNA (GitHub Advisory, LIEF Issue #1277).
The root cause is a NULL pointer dereference (CWE-476) combined with improper resource shutdown or release (CWE-404). When parsing a malformed ELF binary, Parser::parse_gnu_hash fails to initialize the GnuHash structure (logging "Can't read the number of buckets"), but Parser::parse_binary subsequently calls original_size() on the resulting null gnu_hash_ pointer without a null check. The crash occurs at LIEF::ELF::GnuHash::original_size() in include/LIEF/ELF/GnuHash.hpp:136, with AddressSanitizer reporting a SIGSEGV READ at address 0x000000000060 (a member access offset on a null pointer). Exploitation requires local access and the ability to supply a crafted ELF binary to an application using LIEF. A proof-of-concept reproducer file and ASAN report are publicly available (LIEF Issue #1277, LIEF Commit).
Successful exploitation causes a denial of service (application crash) in any application that uses LIEF to parse untrusted or user-supplied ELF binary files. There is no confidentiality or integrity impact — the vulnerability is limited strictly to availability. Systems such as binary analysis pipelines, security tools, or CI/CD environments that process arbitrary ELF files are at highest risk (GitHub Advisory, Feedly).
A proof-of-concept exploit (a malformed ELF binary reproducer) has been publicly released and is referenced in the LIEF GitHub issue and on VulDB. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of widespread exploitation. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access with low privileges (LIEF Issue #1277, VulDB).
.gnu.hash) that causes Parser::parse_gnu_hash to fail reading the number of buckets. A public reproducer is available at https://github.com/oneafter/1210/blob/main/segv1.elf_reader example or a custom binary analysis tool../elf_reader <malformed.elf>.GnuHash::original_size() on a null pointer after parse_gnu_hash fails, resulting in a SIGSEGV and application crash, causing a denial of service (LIEF Issue #1277).LIEF::ELF::GnuHash::original_size() or LIEF::ELF::Parser::parse_binary(); ASAN output containing SEGV on unknown address 0x000000000060..gnu.hash sections) in directories processed by LIEF-based tools; core dump files generated by the affected process (LIEF Issue #1277).Upgrade LIEF to version 0.17.2 or later, which includes the fix in commit 81bd5d7ea0c390563f1c4c017c9019d154802978. The patch adds a null check for binary_->gnu_hash_ before calling original_size(), preventing the crash. As a workaround prior to patching, restrict local access to systems running LIEF-based applications and implement input validation to reject malformed or untrusted ELF files before processing. Monitor for unexpected application crashes that may indicate exploitation attempts (LIEF Release 0.17.2, LIEF Commit).
The vulnerability was labeled "Priority Critical" by the LIEF project maintainers in the GitHub issue tracker, and the fix was merged promptly. The issue was reported by researcher "oneafter" on December 10, 2025, and the patch was released in LIEF 0.17.2 on January 3, 2026. No significant broader media coverage or notable external researcher commentary has been identified beyond standard vulnerability database entries (LIEF Issue #1277, LIEF Release 0.17.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."