CVE detail
CVE-2025-1352
A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Siemens SINEC OSCISA Alerts
Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight soc
governmentwww.cisa.govJul 7, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comFeb 16, 2025, 3:15 PM - https://www.gnu.org/www.gnu.org
No excerpt available.
Third Party Advisorywww.gnu.orgFeb 16, 2025, 3:15 PM - https://vuldb.com/?submit.495965vuldb.com
No excerpt available.
Exploitvuldb.comFeb 16, 2025, 3:15 PM - https://vuldb.com/?id.295960vuldb.com
No excerpt available.
Exploitvuldb.comFeb 16, 2025, 3:15 PM - https://vuldb.com/?ctiid.295960vuldb.com
No excerpt available.
Exploitvuldb.comFeb 16, 2025, 3:15 PM - https://sourceware.org/bugzilla/show_bug.cgi?id=32650#c2sourceware.org
No excerpt available.
Exploitsourceware.orgFeb 16, 2025, 3:15 PM - https://sourceware.org/bugzilla/show_bug.cgi?id=32650sourceware.org
No excerpt available.
Exploitsourceware.orgFeb 16, 2025, 3:15 PM - https://sourceware.org/bugzilla/attachment.cgi?id=15923sourceware.org
No excerpt available.
Exploitsourceware.orgFeb 16, 2025, 3:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-1372CVSS 4.8 · Medium
A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the fil…
- CVE-2025-1365CVSS 4.8 · Medium
A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The…
- CVE-2018-18520CVSS 6.5 · Medium
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle…
- CVE-2018-18310CVSS 5.5 · Medium
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of…
- CVE-2016-10255CVSS 5.5 · Medium
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_…
- CVE-2016-10254CVSS 5.5 · Medium
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELF file, which triggers a memory allocat…