SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-2314

An unprivileged attacker could use this to force bcc to load compromised linux headers.

LOW 2.5EPSS 0.22%

Does this matter?

Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.

Description

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

CVSS 3.1
2.5 LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.22% probability · 12th percentile
CISA KEV
Not listed
Affected
iovisor/bpf compiler collection
Source
security@ubuntu.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.