CVE-2025-29478: Medium severity Fluent Bit Fluent Bit vulnerability
Published Apr 7, 2025
·Updated
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfllistsize in cfllist.h:165.
Affected Software
9 affected components
Fluent Bit Fluent Bit
Microsoft azl3 fluent-bit 3.1.9-6
Microsoft cbl2 fluent-bit 3.0.6-3
Microsoft azl3 fluent-bit 3.1.9-5
Microsoft cbl2 fluent-bit 3.0.6-4
Microsoft cbl2 fluent-bit 3.0.6-2
Microsoft azl3 fluent-bit 3.1.9-4
Microsoft azl3 fluent-bit 3.1.10-2
Treasuredata Fluent Bit
Event History
Apr 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:03 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:03 PM
SeverityAffected Software
Updated
via Microsoft·11:03 PM
DescriptionSeverity
Updated
via Microsoft·11:03 PM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29478?
CVE-2025-29478 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2025-29478?
To mitigate CVE-2025-29478, update Fluent Bit to the latest version where the vulnerability is patched.
3
What impact does CVE-2025-29478 have on Fluent Bit?
CVE-2025-29478 allows a local attacker to cause a denial of service, potentially leading to service interruptions.
4
Is my version of Fluent Bit affected by CVE-2025-29478?
Fluent Bit version 3.7.2 is specifically affected by CVE-2025-29478, along with potentially other versions if not updated.
5
How can I identify an attack exploiting CVE-2025-29478?
Monitoring for unusual resource consumption or unexpected crashes in Fluent Bit may indicate an exploitation of CVE-2025-29478.