8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length. An attacker who can create containers or control container names, can supply a long name that overflows the buffer, leading to process crash or arbitrary code execution.
AI Analysis
Buffer overflow vulnerability in Fluent Bit in_docker input plugin allowing process crash or arbitrary code execution
Basic Information
ID
CVE-2025-12970
Source
certcc
Published
Nov 24, 2025 at 14:39
Modified
Nov 24, 2025 at 17:00
Affected Product
Vendor
FluentBit
Product
FluentBit
Version
4.1.0
Affected Versions
FluentBit FluentBit 4.1.0
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
FluentBit
Product
Fluent Bit
Version
4.1.0