CVE-2025-12970: High severity Fluent Bit Fluent Bit vulnerability
CVE-2025-12970
Other sources
The extractname function in Fluent Bit indocker input plugin copies container names into a fixed size stack buffer without validating length. An attacker who can create containers or control container names, can supply a long name that overflows the buffer, leading to process crash or arbitrary code execution.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12970?
CVE-2025-12970 has a high severity level due to the potential for a buffer overflow leading to process crashes.
How do I fix CVE-2025-12970?
To fix CVE-2025-12970, update to the latest version of Fluent Bit that contains the patch addressing this vulnerability.
Who is affected by CVE-2025-12970?
CVE-2025-12970 affects users of the Fluent Bit in_docker input plugin who can create or control container names.
What type of vulnerability is CVE-2025-12970?
CVE-2025-12970 is a buffer overflow vulnerability due to unchecked name lengths in the Fluent Bit software.
Can CVE-2025-12970 be exploited remotely?
Yes, CVE-2025-12970 can be exploited if an attacker can manipulate container names, which may be remotely controllable.