Two DoS vulnerabilities in readelf 2.46: 1. Resource exhaustion (CWE-400): crafted ELF triggers 6.3TB allocation, OOM kill 2. Null pointer deref (CWE-476): malformed sh_entsize/shoff causes SIGSEGV Discovered via AFL++ fuzzing. PoC files attached to JSM ticket. Not publicly disclosed.
Does this issue affect versions between 2.34 and 2.44? Also, is there an estimated timeline for an upstream fix or patch release?