USN-5759-1: LibBPF vulnerabilities
5 December 2022
Several security issues were fixed in LibBPF.
Releases
Packages
- libbpf - eBPF helper library (development files)
Details
It was discovered that LibBPF incorrectly handled certain memory operations
under certain circumstances. An attacker could possibly use this issue to
cause LibBPF to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2021-45940, CVE-2021-45941, CVE-2022-3533)
It was discovered that LibBPF incorrectly handled certain memory operations
under certain circumstances. An attacker could possibly use this issue to
cause LibBPF to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-3534, CVE-2022-3606)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.
Related notices
- USN-5759-2: libbpf0, libbpf-dev, libbpf
- USN-6215-1: dwarves, dwarves-dfsg