[USN-5759-1] LibBPF vulnerabilities

Severity High
Affected Packages 4
CVEs 5

Several security issues were fixed in LibBPF.

It was discovered that LibBPF incorrectly handled certain memory operations
under certain circumstances. An attacker could possibly use this issue to
cause LibBPF to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2021-45940, CVE-2021-45941, CVE-2022-3533)

It was discovered that LibBPF incorrectly handled certain memory operations
under certain circumstances. An attacker could possibly use this issue to
cause LibBPF to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-3534, CVE-2022-3606)

Package Affected Version
pkg:deb/ubuntu/libbpf0?distro=kinetic < 0.8.0-1ubuntu22.10.1
pkg:deb/ubuntu/libbpf0?distro=jammy < 0.5.0-1ubuntu22.04.1
pkg:deb/ubuntu/libbpf-dev?distro=kinetic < 0.8.0-1ubuntu22.10.1
pkg:deb/ubuntu/libbpf-dev?distro=jammy < 0.5.0-1ubuntu22.04.1
ID
USN-5759-1
Severity
high
Severity from
CVE-2022-3534
URL
https://ubuntu.com/security/notices/USN-5759-1
Published
2022-12-05T08:43:17
(21 months ago)
Modified
2022-12-05T08:43:17
(21 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/libbpf0?distro=kinetic ubuntu libbpf0 < 0.8.0-1ubuntu22.10.1 kinetic
Affected pkg:deb/ubuntu/libbpf0?distro=jammy ubuntu libbpf0 < 0.5.0-1ubuntu22.04.1 jammy
Affected pkg:deb/ubuntu/libbpf-dev?distro=kinetic ubuntu libbpf-dev < 0.8.0-1ubuntu22.10.1 kinetic
Affected pkg:deb/ubuntu/libbpf-dev?distro=jammy ubuntu libbpf-dev < 0.5.0-1ubuntu22.04.1 jammy
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...