CVE-2024-2313
Last modified
CVE-2024-2313 is a low-severity vulnerability rated 2.8/10 on the CVSS scale. If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bpftrace | Bpftrace | < 0.20.2 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2313Third Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2313Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-2313?
How severe is CVE-2024-2313?
How do I fix CVE-2024-2313?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-23124A maliciously crafted STP file, when parsed in ASMIMPORT228A…7.8
- CVE-2024-23125A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll …7.8
- CVE-2024-23126A maliciously crafted CATPART file when parsed CC5Dll.dll th…7.8
- CVE-2024-23127A maliciously crafted MODEL, SLDPRT, or SLDASM file, when pa…7.8
- CVE-2024-23128A maliciously crafted MODEL file, when parsed in libodxdll.d…7.8
- CVE-2024-23129A maliciously crafted MODEL 3DM, STP, or SLDASM file, when i…7.8
- CVE-2024-23130A maliciously crafted SLDASM or SLDPRT file, when parsed in …7.8
- CVE-2024-23131A maliciously crafted STP file, when parsed in ASMIMPORT229A…7.8
- CVE-2024-23132A maliciously crafted STP file in atf_dwg_consumer.dll when …7.8
- CVE-2024-23133A maliciously crafted STP file in ASMDATAX228A.dll when pars…7.8
- CVE-2024-23134A maliciously crafted IGS file in tbb.dll when parsed throug…7.8
- CVE-2024-23135A maliciously crafted SLDPRT file in ASMkern228A.dll when pa…7.8
Are you affected by CVE-2024-2313?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
