Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."
History

Wed, 25 Feb 2026 08:00:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Tue, 15 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Libbpf Project
Libbpf Project libbpf
CPEs cpe:2.3:a:libbpf_project:libbpf:1.5.0:*:*:*:*:*:*:*
Vendors & Products Libbpf Project
Libbpf Project libbpf

Tue, 15 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics threat_severity

Important

threat_severity

Moderate


Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 09 Apr 2025 02:00:00 +0000

Type Values Removed Values Added
Title libbpf: Heap Buffer Overflow in libbpf
Weaknesses CWE-122
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

threat_severity

Important


Mon, 07 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-25T07:51:20.699Z

Reserved: 2025-03-11T00:00:00.000Z

Link: CVE-2025-29481

cve-icon Vulnrichment

Updated: 2025-04-09T15:02:27.833Z

cve-icon NVD

Status : Modified

Published: 2025-04-07T20:15:20.720

Modified: 2026-02-25T08:16:18.860

Link: CVE-2025-29481

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-07T00:00:00Z

Links: CVE-2025-29481 - Bugzilla

cve-icon OpenCVE Enrichment

No data.