In the Linux kernel, the following vulnerability has been resolved:
libbpf: Fix accessing BTF.ext core_relo header
Update btf_ext_parse_info() to ensure the core_relo header is present
before reading its fields. This avoids a potential buffer read overflow
reported by the OSS Fuzz project.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 21 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 20 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: libbpf: Fix accessing BTF.ext core_relo header Update btf_ext_parse_info() to ensure the core_relo header is present before reading its fields. This avoids a potential buffer read overflow reported by the OSS Fuzz project. | |
| Title | libbpf: Fix accessing BTF.ext core_relo header | |
| References |
|
Status: PUBLISHED
Assigner: Linux
Published: 2025-05-20T15:34:41.511Z
Updated: 2025-05-26T05:24:09.065Z
Reserved: 2025-04-16T04:51:23.971Z
Link: CVE-2025-37939
No data.
Status : Analyzed
Published: 2025-05-20T16:15:31.467
Modified: 2025-11-17T14:57:25.150
Link: CVE-2025-37939