USN-7576-1: dwarfutils vulnerabilities

Publication date

18 June 2025

Overview

dwarfutils could be made to crash or run programs as your login if it opened a specially crafted file.


Packages

  • dwarfutils - Utilities for DWARF debugging information

Details

It was discovered that dwarfutils did not correctly certain memory
operations, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code.

It was discovered that dwarfutils did not correctly certain memory
operations, which could lead to a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
25.04 plucky dwarfdump –  20210528-1ubuntu0.25.04.1
libdwarf-dev –  20210528-1ubuntu0.25.04.1
libdwarf1 –  20210528-1ubuntu0.25.04.1
24.10 oracular dwarfdump –  20210528-1ubuntu0.24.10.1
libdwarf-dev –  20210528-1ubuntu0.24.10.1
libdwarf1 –  20210528-1ubuntu0.24.10.1
24.04 noble dwarfdump –  20210528-1ubuntu0.24.04.1~esm1  
libdwarf-dev –  20210528-1ubuntu0.24.04.1~esm1  
libdwarf1 –  20210528-1ubuntu0.24.04.1~esm1  
22.04 jammy dwarfdump –  20210528-1ubuntu0.22.04.1~esm1  
libdwarf-dev –  20210528-1ubuntu0.22.04.1~esm1  
libdwarf1 –  20210528-1ubuntu0.22.04.1~esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›