{"id":"CVE-2024-2314","details":"If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.","modified":"2026-04-12T10:25:02.421799Z","published":"2024-03-10T23:15:53.967Z","related":["ALSA-2024:8831","ALSA-2024:9187"],"references":[{"type":"ADVISORY","url":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2314"},{"type":"FIX","url":"https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/iovisor/bcc","events":[{"introduced":"0"},{"fixed":"e7109fa0f17bdda4de0a7f05b03f563ead0150f4"},{"fixed":"008ea09e891194c072f2a9305a3c872a241dc342"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"0.30.0"}]}}],"versions":["0.29.0","v0.1","v0.1.1","v0.1.2","v0.1.3","v0.1.4","v0.1.5","v0.1.6","v0.1.7","v0.1.8","v0.10.0","v0.11.0","v0.12.0","v0.13.0","v0.14.0","v0.15.0","v0.16.0","v0.17.0","v0.18.0","v0.19.0","v0.2.0","v0.20.0","v0.21.0","v0.22.0","v0.23.0","v0.24.0","v0.25.0","v0.26.0","v0.27.0","v0.28.0","v0.29.0","v0.29.1","v0.3.0","v0.4.0","v0.5.0","v0.6.0","v0.6.1","v0.7.0","v0.8.0","v0.9.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"308716148748540606133817584002692136566","length":113},"id":"CVE-2024-2314-1c2a2150","signature_type":"Function","signature_version":"v1","source":"https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342","target":{"file":"src/cc/frontends/clang/kbuild_helper.cc","function":"file_exists"}},{"deprecated":false,"digest":{"function_hash":"36553956271564276799818680856489912411","length":279},"id":"CVE-2024-2314-44ef7087","signature_type":"Function","signature_version":"v1","source":"https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342","target":{"file":"src/cc/frontends/clang/kbuild_helper.cc","function":"get_proc_kheaders"}},{"signature_version":"v1","source":"https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342","target":{"file":"src/cc/frontends/clang/kbuild_helper.cc","function":"proc_kheaders_exists"},"deprecated":false,"digest":{"function_hash":"176068315365745535262836052478444433058","length":83},"id":"CVE-2024-2314-9cfb27c4","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["203144673931783277252679441464818329457","254514248939720361619626096940303900352","304407264196365778991441667459302027185","198000745905710924416509355846585799580","327793335891738710618898004887903648685","219603813375402378306049359073636592218","60127501487766778599290419140892115467","217952124790708712411794248912960313958","111194669660047849200649400389794245628","284230794198876485759471270740745994755","315588038695568193871764469486784558373","224828295704853230034386982561521009631","252394138666132878342978846779213536240","68029674717479282024606727610100404331","277934550484589590181224682729557060719"],"threshold":0.9},"id":"CVE-2024-2314-9f70d357","signature_type":"Line","signature_version":"v1","source":"https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342","target":{"file":"src/cc/frontends/clang/kbuild_helper.cc"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2314.json","vanir_signatures_modified":"2026-04-12T10:25:02Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}