PT-2025-15283 · Libbpf+1 · Libbpf+1

Published

2025-04-07

·

Updated

2026-02-25

·

CVE-2025-29481

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libbpf version 1.5.0
Description The issue allows a local attacker to execute arbitrary code via the bpf object init prog function of libbpf. This is a Buffer Overflow vulnerability.
Recommendations For libbpf version 1.5.0, as a temporary workaround, consider disabling the bpf object init prog function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-59719
AZL-59727
AZL-59737
AZL-59745
AZL-61765
BIT-BPFTOOL-2025-29481
CVE-2025-29481
ECHO-B8D0-8E49-7598

Affected Products

Debian
Libbpf