← Vulnerability feed

Vulnerability record · CVE-2019-7148 · published 29 January 2019

CVE-2019-7148: Elfutils project elfutils allocation without limits vulnerability

Elfutils Project · Elfutils

An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted elf input, which leads to an out-of-memory exception. NOTE: The maintainers believe this is not a real issue, but instead a "warning caused by ASAN because the allocation is big. By setting ASAN_OPTIONS=allocator_may_return_null=1 and running the reproducer, nothing happens."

6.5 CVSS 3.0 Medium EPSS 1.6% · top 25.2% CWE-770 · Allocation without limits
6.5CVSS 3.0 base score, v2 4.3
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted elf input, which leads to an out-of-memory exception. NOTE: The maintainers believe this is not a real issue, but instead a "warning caused by ASAN because the allocation is big. By setting ASAN_OPTIONS=allocator_may_return_null=1 and running the reproducer, nothing happens."

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://sourceware.org/bugzilla/show_bug.cgi?id=24085 ExploitIssue TrackingThird Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=24085 ExploitIssue TrackingThird Party Advisory

Track CVE-2019-7148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-16402Elfutils project elfutils double free vulnerabilitylibelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif…EPSS 3.7%7.8CVE-2018-8769Elfutils project elfutils out-of-bounds read vulnerabilityelfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.EPSS 0.84%6.8CVE-2014-0172Elfutils project elfutils vulnerabilityInteger overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows…EPSS 4.0%6.5CVE-2019-7149Elfutils project elfutils out-of-bounds read vulnerabilityA heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cau…EPSS 2.2%6.5CVE-2018-18520Elfutils project elfutils memory buffer overflow vulnerabilityAn Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar…EPSS 2.8%6.4CVE-2014-9447Elfutils project elfutils path traversal vulnerabilityDirectory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write …EPSS 5.0%5.5CVE-2020-21047Elfutils project elfutils out-of-bounds write vulnerabilityThe libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by applica…EPSS 0.24%5.5CVE-2021-33294Elfutils project elfutils vulnerabilityIn elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infini…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2019-7148), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.