SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-2313

An unprivileged attacker could use this to force bcc to load compromised linux headers.

LOW 2.8EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS 3.1
2.8 LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS
0.18% probability · 8th percentile
CISA KEV
Not listed
Weakness
CWE-377
Affected
bpftrace/bpftrace
Source
security@ubuntu.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.