elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38203.json"