Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2313

Опубликовано: 10 мар. 2024
Источник: redhat
CVSS3: 2.8

Описание

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

A flaw was found in BPFtrace. This issue occurs when extracting kernel headers, it tries to load them from a temporary directory. This issue could allow an attacker to force bpftrace to load compromised Linux headers by placing malicious headers in the temporary directory, leading to potential security risks, unauthorized access, or system compromise.

Отчет

This flaw is triggered by handling malicious input and the overall impact is considered minimal.

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2269014bpftrace: unprivileged users can force loading of compromised linux headers

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
nvd
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 2.8
debian
больше 1 года назад

If kernel headers need to be extracted, bpftrace will attempt to load ...

rocky
7 месяцев назад

Low: bpftrace security update

2.8 Low

CVSS3