bpftrace-0.21.1-1.el9

エラータID: AXSA:2024-9422:04

Release date: 
Thursday, December 19, 2024 - 22:25
Subject: 
bpftrace-0.21.1-1.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Low
Description: 

BPFtrace is a high-level tracing language for Linux enhanced Berkeley Packet Filter (eBPF) available in recent Linux kernels (4.x). BPFtrace uses LLVM as a backend to compile scripts to BPF-bytecode and makes use of BCC for interacting with the Linux BPF system, as well as existing Linux tracing capabilities: kernel dynamic tracing (kprobes), user-level dynamic tracing (uprobes), and tracepoints. The BPFtrace language is inspired by awk and C, and predecessor tracers such as DTrace and SystemTap

Security Fix(es):

* bpftrace: unprivileged users can force loading of compromised linux headers (CVE-2024-2313)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.5 Release Notes linked from the References section.

CVE-2024-2313
If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. bpftrace-0.21.1-1.el9.src.rpm
    MD5: daa2211d14988e767e20b688c4809f66
    SHA-256: 29f76420ae9ace631927286fff9d16e8f28e613fc3e511bb3216ec90f24c85e5
    Size: 1.61 MB

Asianux Server 9 for x86_64
  1. bpftrace-0.21.1-1.el9.x86_64.rpm
    MD5: 332ae68e789a4feb4f8583a62d5abd36
    SHA-256: 0d30ca541440b35bbda68c9b3db22e1ddbd1ee6d55383c80685b44327cb07563
    Size: 1.75 MB