Details at $URL.
@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
CVE ID: CVE-2016-10255
Summary: The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
This issue was resolved and addressed in
GLSA 201710-10 at https://security.gentoo.org/glsa/201710-10
by GLSA coordinator Aaron Bauman (b-man).