Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-9188

Опубликовано: 14 нояб. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-9188: bpftrace security update (LOW)

[0.21.1-1]

  • Rebase on bpftrace 0.21.1
  • Add LLVM 18 support (RHEL-28685)

[0.20.4-3]

  • Fix latest build (not built in side tag)

[0.20.4-2]

  • Rebuild for bcc 0.30.0-4

[0.20.4-1]

  • Rebase on bpftrace 0.20.4
  • Fix CVE allowing unprivileged users loading of compromised linux headers (RHEL-28765, CVE-2024-2313)

[ - 0.20.3-1]

  • Rebase on bpftrace 0.20.3 (RHEL-30779)
  • Fix CVE allowing unprivileged users loading of compromised linux headers (RHEL-28765, CVE-2024-2313)
  • Fix bpftrace creating BPF programs with truncated names (RHEL-8502)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

bpftrace

0.21.1-1.el9

Oracle Linux x86_64

bpftrace

0.21.1-1.el9

Связанные CVE

Связанные уязвимости

CVSS3: 2.8
ubuntu
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
redhat
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
nvd
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 2.8
debian
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load ...