Описание
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
A flaw was found in the cilium/ebpf Go library (versions up to 0.21.0). An integer overflow in the loadRawSpec function (btf/btf.go) when parsing BTF collection specs can cause excessive memory allocation or parsing failure. A local attacker who can supply a crafted eBPF collection spec to an application using this library could trigger a denial of service.
Отчет
The cilium/ebpf library is vulnerable to an integer overflow in loadRawSpec when loading BTF collection specifications. A local attacker with low privileges who can provide a malicious collection spec to a process that uses LoadCollectionSpec or LoadCollectionSpecFromReader can cause denial of service (availability impact only). CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5). Affects Red Hat products that bundle github.com/cilium/ebpf, including OpenShift, CNV, bpfman, network observability, and other container/runtime components.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-monitor-rhel9 | Under investigation | ||
| Multiarch Tuning Operator | multiarch-tuning/multiarch-tuning-operator-bundle | Under investigation | ||
| Multiarch Tuning Operator | multiarch-tuning/multiarch-tuning-rhel9-operator | Under investigation | ||
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Under investigation | ||
| Network Observability Operator | network-observability/network-observability-ebpf-agent-rhel9 | Under investigation | ||
| Network Observability Operator | network-observability/network-observability-flowlogs-pipeline-rhel9 | Under investigation | ||
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-cni-rhel8 | Under investigation | ||
| OpenShift Service Mesh 2 | openshift-service-mesh/pilot-rhel8 | Under investigation | ||
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel9 | Under investigation | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | redhat-user-workloads/prometheus-acm-211 | Under investigation |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
A vulnerability has been found in cilium ebpf up to 0.21.0. This affec ...
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
EPSS
5.5 Medium
CVSS3