Vulnerability Description
libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (4 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libbpf Project | Libbpf | 0.6.0 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=40868ExploitIssue TrackingThird Party Advisory
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libbpf/OSV-2021-1562.yaExploitThird Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=40868ExploitIssue TrackingThird Party Advisory
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libbpf/OSV-2021-1562.yaExploitThird Party Advisory
FAQ
What is CVE-2021-45940?
CVE-2021-45940 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (4 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).
How severe is CVE-2021-45940?
CVE-2021-45940 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45940?
Check the references section above for vendor advisories and patch information. Affected products include: Libbpf Project Libbpf.