CVE-2024-2314
Last modified
CVE-2024-2314 is a low-severity vulnerability rated 2.5/10 on the CVSS scale. If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iovisor | Bpf Compiler Collection | < 0.30.0 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2314Third Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2314Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-2314?
How severe is CVE-2024-2314?
How do I fix CVE-2024-2314?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-23134A maliciously crafted IGS file in tbb.dll when parsed throug…7.8
- CVE-2024-23135A maliciously crafted SLDPRT file in ASMkern228A.dll when pa…7.8
- CVE-2024-23136A maliciously crafted STP file in ASMKERN228A.dll when parse…7.8
- CVE-2024-23137A maliciously crafted STP or SLDPRT file, when parsed in ODX…7.8
- CVE-2024-23138A maliciously crafted DWG file when parsed through Autodesk …7.8
- CVE-2024-23139A maliciously crafted ABC file, when parsed through Autodesk…7.8
- CVE-2024-23140A maliciously crafted 3DM and MODEL file, when parsed in ope…7.8
- CVE-2024-23141A maliciously crafted MODEL file, when parsed in libodxdll t…7.8
- CVE-2024-23142A maliciously crafted CATPART, STP, and MODEL file, when par…7.8
- CVE-2024-23143A maliciously crafted 3DM, MODEL and X_B file, when parsed i…7.8
- CVE-2024-23144A maliciously crafted CATPART file, when parsed in CC5Dll.dl…7.8
- CVE-2024-23145A maliciously crafted PRT file, when parsed in opennurbs.dll…7.8
Are you affected by CVE-2024-2314?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
