CVE-2025-2849
A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2. It is recommended to apply a patch to fix this issue.
- Upx
- ≤ 5.0.0
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.3% (22th percentile)
- Weakness
- CWE-119, CWE-787, CWE-122
- NVD status
- Analyzed
- Published
- 2025-03-27
CVE-2025-2849 at NVD
No indexed exploits for CVE-2025-2849 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-2849 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.