CVE-2019-7664: Elfutils Project Elfutils
Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
Affected products
- Elfutils Project Elfutils: version 0.175 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2019-02-09. Last modified 2026-06-17.