CVE-2019-7149

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-7149

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201903-9

OS impact

OSVersionStatusFixed in
arch archfixed0.176-1
debian debianbookwormfixed0.176-1
debian debianbullseyefixed0.176-1
debian debianforkyfixed0.176-1
debian debiansidfixed0.176-1
debian debiantrixiefixed0.176-1

References

Verify integrity in audit chain (admin only). AS-IS.