cbcvebase.
CVE-2025-29481
published 2025-04-07

CVE-2025-29481: Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has…

PriorityP424medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.23%
13.9th percentile
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibbpf< libbpf 1.5.0-3 (forky)libbpf 1.5.0-3 (forky)
libbpf_projectlibbpf
libbpf_projectlibbpf>= 0 < 1.5.0-31.5.0-3
libbpf_projectlibbpf>= 0 < 1.5.0-31.5.0-3
msrcazl3_bcc_0.29.1-3_on_azure_linux_3.0
msrcazl3_dwarves_1.25-2_on_azure_linux_3.0
msrcazl3_libbpf_1.2.2-2_on_azure_linux_3.0
msrcazl3_xdp-tools_1.4.2-1_on_azure_linux_3.0
msrccbl2_libbpf_1.0.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2LOW
vendor_msrc6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.