CVE-2025-29481

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:libbpf_project:libbpf:1.5.0:*:*:*:*:*:*:*

History

15 Apr 2025, 15:42

Type Values Removed Values Added
References () https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md - () https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md - Third Party Advisory, Exploit
CPE cpe:2.3:a:libbpf_project:libbpf:1.5.0:*:*:*:*:*:*:*
First Time Libbpf Project libbpf
Libbpf Project

09 Apr 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2
References () https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md - () https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md -
CWE CWE-120

08 Apr 2025, 18:13

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de desbordamiento de búfer en libbpf 1.5.0 permite a un atacante local ejecutar código arbitrario a través de la función bpf_object__init_prog` de libbpf.

07 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-07 20:15

Updated : 2025-04-15 15:42


NVD link : CVE-2025-29481

Mitre link : CVE-2025-29481

CVE.ORG link : CVE-2025-29481


JSON object : View

Products Affected

libbpf_project

  • libbpf
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')