Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfpq-px23-jj9f

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 8

Описание

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

EPSS

Процентиль: 58%
0.00905
Низкий

5.1 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-119
CWE-416

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

CVSS3: 4.3
redhat
почти 4 года назад

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

CVSS3: 5.5
nvd
почти 4 года назад

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8/fbe08093fb2334549859829ef81d42570812597d/8c64a8e76eb85d422af5ec60ccbf26e3ead8c333/a733bf10198eb5bb927890940de8ab457491ed3b/93c660ca40b5d2f7c1b1626e955a8e9fa30e0749. You should upgrade the affected component.

CVSS3: 5.5
debian
почти 4 года назад

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/ ...

CVSS3: 8
fstec
почти 4 года назад

Уязвимость функции btf_dump_name_dups() в модуле tools/lib/bpf/btf_dump.c библиотеки libbpf (Berkeley Packet Filters) ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 58%
0.00905
Низкий

5.1 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-119
CWE-416