CVE-2025-2849 | UPX up to 5.0.0 src/p_lx_elf.cpp un_DT_INIT heap-based overflow (Issue 898 / Nessus ID 275970)
A vulnerability has been found in UPX up to 5.0.0 and classified as critical. Impacted is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2025-2849. The attack must be carried out locally. In addition, an exploit is available.
Applying a patch is the recommended action to fix this issue.