Note:
This project will be discontinued after December 13, 2021. [more]
2019-05-17
An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine.
Products | Falco |
Type | Use After Free (CWE-416) |
First patch | - None (likely due to unavailable code) |
Links |
• https://www.twistlock.com/labs-blog/falco-vulnerability-cve-2019-8339/
• https://sysdig.com/blog/cve-2019-8339-falco-vulnerability/ • https://github.com/falcosecurity/falco/pull/561 • https://falco.org/docs/event-sources/dropped-events/ |