PT-2021-24329 · Libbpf+4 · Libbpf+4

Published

2021-12-31

·

Updated

2024-07-01

·

CVE-2021-45940

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libbpf versions 0.6.0 through 0.6.1
Description: The issue is a heap-based buffer overflow of 4 bytes in the bpf object open function, which is called from bpf object open mem and bpf-object-fuzzer.c. This overflow can potentially lead to memory corruption and other security issues.
Recommendations: For libbpf versions 0.6.0 and 0.6.1, consider applying a patch or updating to a version where this issue is fixed, if available. As a temporary workaround, consider restricting access to the bpf object open function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1956
BIT-BPFTOOL-2021-45940
CVE-2021-45940
OPENSUSE-SU-2024:12491-1
USN-5759-1

Affected Products

Alt Linux
Debian
Linuxmint
Ubuntu
Libbpf