CVE-2024-2314
2.5
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.0 / Impact: 1.4
Source: NVD
Description
If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
Affected (1)
Products: Iovisor: Bpf Compiler Collection
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 0.30.0 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
References (4)
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Timeline
No history available yet.