PT-2021-24330 · Libbpf+4 · Libbpf+4

Published

2021-12-31

·

Updated

2024-07-01

·

CVE-2021-45941

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libbpf versions 0.6.0 through 0.6.1
Description: The issue is a heap-based buffer overflow of 8 bytes in the bpf object open function, which is called from bpf object open mem and bpf-object-fuzzer.c.
Recommendations: For libbpf versions 0.6.0 and 0.6.1, consider restricting access to the bpf object open function until a patch is available. As a temporary workaround, avoid using the bpf object open mem and bpf-object-fuzzer.c functions that call bpf object open until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1956
BIT-BPFTOOL-2021-45941
CVE-2021-45941
USN-5759-1

Affected Products

Alt Linux
Debian
Linuxmint
Ubuntu
Libbpf