Resource Exhaustion Affecting bpftool package, versions *
Threat Intelligence
EPSS
0.04% (12th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS7-BPFTOOL-6742663
- published 30 Apr 2024
- disclosed 28 Apr 2024
Introduced: 28 Apr 2024
CVE-2022-48641 Open this link in a new tabHow to fix?
There is no fixed version for Centos:7
bpftool
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream bpftool
package and not the bpftool
package as distributed by Centos
.
See How to fix?
for Centos:7
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: fix memory leak when blob is malformed
The bug fix was incomplete, it "replaced" crash with a memory leak. The old code had an assignment to "ret" embedded into the conditional, restore this.
References
- https://access.redhat.com/security/cve/CVE-2022-48641
- https://git.kernel.org/stable/c/11ebf32fde46572b0aaf3c2bdd97d923ef5a03ab
- https://git.kernel.org/stable/c/1e98318af2f163eadaff815abcef38d27ca92c1e
- https://git.kernel.org/stable/c/38cf372b17f0a5f35c1b716a100532d539f0eb33
- https://git.kernel.org/stable/c/62ce44c4fff947eebdf10bb582267e686e6835c9
- https://git.kernel.org/stable/c/754e8b74281dd54a324698803483f47cf3355ae1
- https://git.kernel.org/stable/c/d5917b7af7cae0e2804f9d127a03268035098b7f
- https://git.kernel.org/stable/c/ebd97dbe3c55d68346b9c5fb00634a7f5b10bbee
CVSS Scores
version 3.1