elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
{
"availability": "No subscription required",
"priority_reason": "No security impact per upstream elfutils developers",
"binaries": [
{
"binary_name": "debuginfod",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "elfutils",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libasm-dev",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libasm1t64",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libdebuginfod-common",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libdebuginfod-dev",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libdebuginfod1t64",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libdw-dev",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libdw1t64",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libelf-dev",
"binary_version": "0.190-1.1ubuntu0.1"
},
{
"binary_name": "libelf1t64",
"binary_version": "0.190-1.1ubuntu0.1"
}
]
}