Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8235

Опубликовано: 30 авг. 2024
Источник: nvd
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*
Версия от 10.4.0 (включая) до 10.7.0 (исключая)
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 30%
0.00106
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-476
CWE-476

Связанные уязвимости

CVSS3: 6.2
ubuntu
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

CVSS3: 6.2
redhat
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

CVSS3: 6.2
debian
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list ...

CVSS3: 6.2
redos
11 месяцев назад

Уязвимость libvirt

CVSS3: 6.2
github
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

EPSS

Процентиль: 30%
0.00106
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-476
CWE-476