Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2313

Опубликовано: 10 мар. 2024
Источник: redhat
CVSS3: 2.8

Описание

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

A flaw was found in BPFtrace. This issue occurs when extracting kernel headers, it tries to load them from a temporary directory. This issue could allow an attacker to force bpftrace to load compromised Linux headers by placing malicious headers in the temporary directory, leading to potential security risks, unauthorized access, or system compromise.

Отчет

This flaw is triggered by handling malicious input and the overall impact is considered minimal.

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2269014bpftrace: unprivileged users can force loading of compromised linux headers

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
почти 2 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
nvd
почти 2 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 2.8
debian
почти 2 года назад

If kernel headers need to be extracted, bpftrace will attempt to load ...

rocky
11 месяцев назад

Low: bpftrace security update

2.8 Low

CVSS3