CVE-2025-15504: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-15504 is a null pointer dereference vulnerability in the ELF Binary Parser component of lief-project LIEF (Library to Instrument Executable Formats). It affects all versions up to and including 0.17.1, specifically in the Parser::parse_binary function within src/ELF/Parser.tcc. The vulnerability was reported on December 10, 2025, and publicly disclosed on January 10, 2026, with a fix released in version 0.17.2. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 1.9 (Low) under CVSS v4.0 per the CNA (GitHub Advisory, LIEF Issue #1277).

Technical details

The root cause is a NULL pointer dereference (CWE-476) combined with improper resource shutdown or release (CWE-404). When parsing a malformed ELF binary, Parser::parse_gnu_hash fails to initialize the GnuHash structure (logging "Can't read the number of buckets"), but Parser::parse_binary subsequently calls original_size() on the resulting null gnu_hash_ pointer without a null check. The crash occurs at LIEF::ELF::GnuHash::original_size() in include/LIEF/ELF/GnuHash.hpp:136, with AddressSanitizer reporting a SIGSEGV READ at address 0x000000000060 (a member access offset on a null pointer). Exploitation requires local access and the ability to supply a crafted ELF binary to an application using LIEF. A proof-of-concept reproducer file and ASAN report are publicly available (LIEF Issue #1277, LIEF Commit).

Impact

Successful exploitation causes a denial of service (application crash) in any application that uses LIEF to parse untrusted or user-supplied ELF binary files. There is no confidentiality or integrity impact — the vulnerability is limited strictly to availability. Systems such as binary analysis pipelines, security tools, or CI/CD environments that process arbitrary ELF files are at highest risk (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit (a malformed ELF binary reproducer) has been publicly released and is referenced in the LIEF GitHub issue and on VulDB. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of widespread exploitation. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access with low privileges (LIEF Issue #1277, VulDB).

Exploitation steps

  1. Prepare a malformed ELF binary: Craft or obtain a specially malformed ELF binary with a corrupted or truncated GNU Hash section (.gnu.hash) that causes Parser::parse_gnu_hash to fail reading the number of buckets. A public reproducer is available at https://github.com/oneafter/1210/blob/main/segv1.
  2. Identify a target application: Locate a locally accessible application or script that uses LIEF (versions ≤ 0.17.1) to parse ELF binaries — such as the bundled elf_reader example or a custom binary analysis tool.
  3. Supply the malformed binary: Execute the target application with the crafted ELF file as input, e.g., ./elf_reader <malformed.elf>.
  4. Trigger the crash: The parser attempts to call GnuHash::original_size() on a null pointer after parse_gnu_hash fails, resulting in a SIGSEGV and application crash, causing a denial of service (LIEF Issue #1277).

Indicators of compromise

  • Logs: Application crash logs or core dumps referencing LIEF::ELF::GnuHash::original_size() or LIEF::ELF::Parser::parse_binary(); ASAN output containing SEGV on unknown address 0x000000000060.
  • Process: Unexpected termination (SIGSEGV/signal 11) of processes that invoke LIEF ELF parsing; crash reports from binary analysis tools or pipelines.
  • File System: Presence of suspicious or malformed ELF files (e.g., with truncated or zeroed .gnu.hash sections) in directories processed by LIEF-based tools; core dump files generated by the affected process (LIEF Issue #1277).

Mitigation and workarounds

Upgrade LIEF to version 0.17.2 or later, which includes the fix in commit 81bd5d7ea0c390563f1c4c017c9019d154802978. The patch adds a null check for binary_->gnu_hash_ before calling original_size(), preventing the crash. As a workaround prior to patching, restrict local access to systems running LIEF-based applications and implement input validation to reject malformed or untrusted ELF files before processing. Monitor for unexpected application crashes that may indicate exploitation attempts (LIEF Release 0.17.2, LIEF Commit).

Community reactions

The vulnerability was labeled "Priority Critical" by the LIEF project maintainers in the GitHub issue tracker, and the fix was merged promptly. The issue was reported by researcher "oneafter" on December 10, 2025, and the patch was released in LIEF 0.17.2 on January 3, 2026. No significant broader media coverage or notable external researcher commentary has been identified beyond standard vulnerability database entries (LIEF Issue #1277, LIEF Release 0.17.2).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management