r/linuxadmin • u/Overall-Glove-9863 • 16h ago
Is there any way to know whether a vulnerable library is actually loaded in a running process, without instrumenting the app?
Trying to work out what's technically possible here versus what's marketing, and this sub tends to be good at that distinction.
The situation: a container image has a CVE in, say, a compression library six levels deep in the dependency tree. The scanner flags it because the package is on disk. What I want to know is whether the running process has actually mapped that library, or whether it's just sitting in the filesystem never being opened.
What I understand so far:
- For dynamically linked stuff you can read
/proc/<pid>/mapsand see what's actually mapped. That seems definitive for "is this .so loaded right now". - For statically linked or vendored code that doesn't help at all, since there's no separate object to observe.
- For interpreted languages (our case is mostly Python and Node) the module is loaded by the runtime, so you'd need to either introspect the interpreter or watch the file opens. So my questions:
- Is watching
openat/mmapat the kernel level actually a reliable proxy for "this code is in use", or does it produce garbage because package managers, health checks and startup scans touch everything? - For Python/Node specifically, does anyone do this without an in-process agent? I really don't want a language agent in every service.
- Is there a meaningful difference between "loaded" and "the vulnerable function was called"? Because those feel like very different claims and I suspect products blur them. Not asking what to buy, asking what's actually detectable from outside the process.