Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4418

Опубликовано: 02 мая 2024
Источник: redhat
CVSS3: 6.2

Описание

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the data pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtWill not fix
Red Hat Enterprise Linux 8virt-develFixedRHSA-2024:435108.07.2024
Red Hat Enterprise Linux 8virtFixedRHSA-2024:435108.07.2024
Red Hat Enterprise Linux 9libvirtFixedRHSA-2024:475723.07.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportlibvirtFixedRHSA-2024:443209.07.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2278616libvirt: stack use-after-free in virNetClientIOEventLoop()

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 1 года назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
nvd
около 1 года назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
msrc
около 1 года назад

Описание отсутствует

CVSS3: 6.2
debian
около 1 года назад

A race condition leading to a stack use-after-free flaw was found in l ...

suse-cvrf
около 1 года назад

Security update for libvirt

6.2 Medium

CVSS3