
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2025-37939) was identified in the Linux kernel's libbpf component, specifically in the btf_ext_parse_info() function. The vulnerability was discovered and reported by the OSS Fuzz project and disclosed on May 20, 2025. The issue affects the BTF.ext core_relo header processing in the Linux kernel (NVD, Wiz).
The vulnerability exists in the btf_ext_parse_info() function where it fails to properly validate the presence of the core_relo header before attempting to read its fields. This oversight can lead to a potential buffer read overflow condition. According to Red Hat's assessment, the vulnerability has been assigned a CVSS 3.1 base score of 5.5 with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).
The vulnerability could potentially lead to a buffer read overflow, which might allow attackers to access memory contents beyond the intended boundaries. This could result in information disclosure or system instability (Wiz).
The vulnerability has been resolved in the Linux kernel through a patch that updates the btf_ext_parse_info() function to properly verify the presence of the core_relo header before accessing its fields (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."