Low: bpftrace security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:8830", "synopsis": "Low: bpftrace security update", "severity": "SEVERITY_LOW", "topic": "An update is available for bpftrace.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "BPFtrace is a high-level tracing language for Linux enhanced Berkeley Packet Filter (eBPF) available in recent Linux kernels (4.x). BPFtrace uses LLVM as a backend to compile scripts to BPF-bytecode and makes use of BCC for interacting with the Linux BPF system, as well as existing Linux tracing capabilities: kernel dynamic tracing (kprobes), user-level dynamic tracing (uprobes), and tracepoints. The BPFtrace language is inspired by awk and C, and predecessor tracers such as DTrace and SystemTap\n\nSecurity Fix(es):\n\n* bpftrace: unprivileged users can force loading of compromised linux headers (CVE-2024-2313)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2269014", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2269014", "description": ""}], "cves": [{"name": "CVE-2024-2313", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-2313", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-11-08T15:56:47.559546Z", "rpms": {"Rocky Linux 8": {"nvras": ["bpftrace-0:0.16.0-6.el8_10.x86_64.rpm", "bpftrace-debuginfo-0:0.16.0-6.el8_10.aarch64.rpm", "bpftrace-0:0.16.0-6.el8_10.aarch64.rpm", "bpftrace-0:0.16.0-6.el8_10.src.rpm", "bpftrace-debuginfo-0:0.16.0-6.el8_10.x86_64.rpm", "bpftrace-debugsource-0:0.16.0-6.el8_10.aarch64.rpm","bpftrace-debugsource-0:0.16.0-6.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A recent security bulletin concerning Rocky Linux highlights a minor risk associated with bpftrace that could affect non-privileged users.. Rocky Linux, bpftrace, security advisory, system update, low severity. . Severity: Low. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8830 http://linux.oracle.com/errata/ELSA-2024-8830.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftrace-0.16.0-6.el8_10.x86_64.rpm aarch64: bpftrace-0.16.0-6.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//bpftrace-0.16.0-6.el8_10.src.rpm Related CVEs: CVE-2024-2313 Description of changes: [0.16.0-6] - Fix security hole checking unpacked kernel headers (CVE-2024-2313) - Resolves: RHEL-28764 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.