Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2496

Опубликовано: 26 фев. 2024
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8virt:rhel/libvirtWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtWill not fix
Red Hat Enterprise Linux 9libvirtFixedRHSA-2024:223630.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2269672libvirt: NULL pointer dereference in udevConnectListAllInterfaces()

EPSS

Процентиль: 6%
0.00028
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5
nvd
больше 1 года назад

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 5
debian
больше 1 года назад

A NULL pointer dereference flaw was found in the udevConnectListAllInt ...

CVSS3: 5
github
больше 1 года назад

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

EPSS

Процентиль: 6%
0.00028
Низкий

5 Medium

CVSS3