CVE-2016-10255 PUBLISHED

The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.

EPSS 0.54% · 67.3th percentile

Risk Scores

EPSS Score
0.54%
67.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSelfutils0, 0.157-1ubuntu1, 0.158-0ubuntu3
Ubuntu:16.04:LTSelfutils0, 0.163-4ubuntu1, 0.163-5.1

Timeline

References

Open in Interactive Console →