Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2314

Опубликовано: 10 мар. 2024
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

A flaw was found in the BCC toolset. This issue occurs when extracting kernel headers, it tries to load them from a temporary directory. This issue could allow an attacker to force bcc to load compromised Linux headers by placing malicious headers in the temporary directory, leading to potential security risks, unauthorized access, or system compromise.

Отчет

This flaw is triggered by handling malicious input and the overall impact is considered minimal.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7bccOut of support scope
Red Hat Enterprise Linux 8bccFixedRHSA-2024:883105.11.2024
Red Hat Enterprise Linux 9bccFixedRHSA-2024:918712.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2269019bcc: unprivileged users can force loading of compromised linux headers

EPSS

Процентиль: 7%
0.00029
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
больше 1 года назад

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
nvd
больше 1 года назад

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS3: 2.8
debian
больше 1 года назад

If kernel headers need to be extracted, bcc will attempt to load them ...

rocky
7 месяцев назад

Low: bcc security update

CVSS3: 2.8
github
больше 1 года назад

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

EPSS

Процентиль: 7%
0.00029
Низкий

2.8 Low

CVSS3