The vendor explicitly identifies these products as affected by this CVE.
- elfutils-debuginfod as a component of Red Hat Enterprise Linux 10
- elfutils-debuginfod-client as a component of Red Hat Enterprise Linux 10
- elfutils-debuginfod-client-devel as a component of Red Hat Enterprise Linux 10
- elfutils-default-yama-scope as a component of Red Hat Enterprise Linux 10
- elfutils-devel as a component of Red Hat Enterprise Linux 10
- elfutils-libelf as a component of Red Hat Enterprise Linux 10
- elfutils-libelf-devel as a component of Red Hat Enterprise Linux 10
- elfutils-libs as a component of Red Hat Enterprise Linux 10
- elfutils.src as a component of Red Hat Enterprise Linux 10
- elfutils-debuginfod as a component of Red Hat Enterprise Linux 9
- elfutils-debuginfod-client as a component of Red Hat Enterprise Linux 9
- elfutils-debuginfod-client-devel as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in GNU elfutils. This vulnerability allows a NULL pointer dereference via the handle_dynamic_symtab function in readelf.c.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
