id: PYSEC-2026-1538 published: "2026-07-07T16:03:17.881535Z" modified: "2026-07-07T17:24:30.564215Z" aliases: - CVE-2025-15504 - GHSA-mjjp-xjfg-97wg summary: LIEF is vulnerable to segmentation fault details: A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.17.2 can resolve this issue. The patch is identified as 81bd5d7ea0c390563f1c4c017c9019d154802978. It is recommended to upgrade the affected component. affected: - package: name: lief ecosystem: PyPI purl: pkg:pypi/lief ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.17.2 versions: - 0.10.0 - 0.10.1 - 0.11.0 - 0.11.1 - 0.11.2 - 0.11.3 - 0.11.4 - 0.11.5 - 0.12.0 - 0.12.1 - 0.12.2 - 0.12.3 - 0.13.0 - 0.13.1 - 0.13.2 - 0.14.0 - 0.14.1 - 0.15.0 - 0.15.1 - 0.16.0 - 0.16.1 - 0.16.2 - 0.16.3 - 0.16.4 - 0.16.5 - 0.16.6 - 0.16.7 - 0.17.0 - 0.17.1 - 0.8.0 - 0.8.1 - 0.8.2 - 0.8.3 - 0.9.0 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-15504 - type: WEB url: https://github.com/lief-project/LIEF/issues/1277 - type: WEB url: "https://github.com/lief-project/LIEF/issues/1277#issuecomment-3693859001" - type: WEB url: https://github.com/lief-project/LIEF/commit/81bd5d7ea0c390563f1c4c017c9019d154802978 - type: PACKAGE url: https://github.com/lief-project/LIEF - type: WEB url: https://github.com/lief-project/LIEF/releases/tag/0.17.2 - type: WEB url: https://github.com/oneafter/1210/blob/main/segv1 - type: WEB url: https://vuldb.com/?ctiid.340375 - type: WEB url: https://vuldb.com/?id.340375 - type: WEB url: https://vuldb.com/?submit.733329 - type: PACKAGE url: https://pypi.org/project/lief - type: ADVISORY url: https://github.com/advisories/GHSA-mjjp-xjfg-97wg severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L - type: CVSS_V4 score: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P