CVE-2025-29481: Buffer Overflow
Published Apr 7, 2025
·Updated
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpfobjectinitprog function of libbpf.
Affected Software
7 affected componentsFixes available
libbpf libbpf=1.5.0
F5 Traffix SDC=5.2.0
Libbpf Project Libbpf=1.5.0
Microsoft azl3 bcc 0.29.1-3
Microsoft azl3 dwarves 1.25-2
Microsoft cbl2 libbpf 1.0.1-2
Microsoft azl3 libbpf 1.2.2-2
Event History
Apr 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
May 5, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Oct 10, 2025
Advisory Published
via F5·01:42 PM
Data Sourced
via F5·01:42 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29481?
CVE-2025-29481 is classified as a critical severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
2
How do I fix CVE-2025-29481?
To fix CVE-2025-29481, update the libbpf library to version 1.5.1 or later, or apply any relevant patches provided by the vendor.
3
What systems are affected by CVE-2025-29481?
CVE-2025-29481 affects libbpf version 1.5.0, as well as certain Microsoft products that utilize this library.
4
Who can exploit CVE-2025-29481?
CVE-2025-29481 can be exploited by local attackers who have access to the affected systems.
5
What is the impact of CVE-2025-29481 on affected systems?
Exploitation of CVE-2025-29481 can lead to arbitrary code execution on affected systems, compromising their integrity and security.