net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when showing interfaces. `get_name()` in `interface.c` copies interface labels from `/proc/net/dev` into a fixed 16-byte stack buffer without bounds checking, leading to possible arbitrary code execution or crash. The known attack path does not require privilege but also does not provide privilege escalation in this scenario. A patch is available and expected to be part of version 2.20.
History

Fri, 16 May 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 15 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 May 2025 23:15:00 +0000

Type Values Removed Values Added
Description net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when showing interfaces. `get_name()` in `interface.c` copies interface labels from `/proc/net/dev` into a fixed 16-byte stack buffer without bounds checking, leading to possible arbitrary code execution or crash. The known attack path does not require privilege but also does not provide privilege escalation in this scenario. A patch is available and expected to be part of version 2.20.
Title net-tools Stack-based Buffer Overflow vulnerability
Weaknesses CWE-121
CWE-20
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-14T22:59:19.997Z

Updated: 2025-05-15T15:36:08.950Z

Reserved: 2025-04-30T19:41:58.136Z

Link: CVE-2025-46836

cve-icon Vulnrichment

Updated: 2025-05-15T15:36:05.685Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-14T23:15:48.073

Modified: 2025-05-16T14:43:26.160

Link: CVE-2025-46836

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-14T22:59:19Z

Links: CVE-2025-46836 - Bugzilla