elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
{
"binaries": [
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "debuginfod"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "elfutils"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libasm-dev"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libasm1t64"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libdebuginfod-common"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libdebuginfod-dev"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libdebuginfod1t64"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libdw-dev"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libdw1t64"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libelf-dev"
},
{
"binary_version": "0.190-1.1ubuntu0.1",
"binary_name": "libelf1t64"
}
],
"priority_reason": "No security impact per upstream elfutils developers",
"availability": "No subscription required"
}