Bug 1240236 (CVE-2025-2849) - VUL-0: CVE-2025-2849: upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow
Summary: VUL-0: CVE-2025-2849: upx: UPX p_lx_elf.cpp un_DT_INIT heap-based overflow
Status: RESOLVED FIXED
Alias: CVE-2025-2849
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Jan Engelhardt
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/447180/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-03-28 08:50 UTC by SMASH SMASH
Modified: 2025-10-20 08:00 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2025-03-28 08:50:01 UTC
A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2. It is recommended to apply a patch to fix this issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2025-2849
https://github.com/CVEProject/cvelistV5/blob/main//cves/2025/2xxx/CVE-2025-2849.json
https://www.cve.org/CVERecord?id=CVE-2025-2849
https://github.com/upx/upx/commit/e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2
https://github.com/upx/upx/issues/898
https://github.com/upx/upx/issues/898#issuecomment-2734082143
https://github.com/user-attachments/files/19307868/input.zip
https://vuldb.com/?ctiid.301494
https://vuldb.com/?id.301494
https://vuldb.com/?submit.522371
https://bugzilla.redhat.com/show_bug.cgi?id=2355330
Comment 1 OBSbugzilla Bot 2025-03-28 12:25:04 UTC
This is an autogenerated message for OBS integration:
This bug (1240236) was mentioned in
https://build.opensuse.org/request/show/1265185 Factory / upx
https://build.opensuse.org/request/show/1265186 15.6 / upx
Comment 2 Marcus Meissner 2025-07-26 13:06:20 UTC
openSUSE-SU-2025:0164-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1240236
CVE References: CVE-2025-2849
JIRA References: 
Sources used:
openSUSE Leap 15.6 (src):    upx-5.0.0-lp156.3.3.1