Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4418

Опубликовано: 02 мая 2024
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the data pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtWill not fix
Red Hat Enterprise Linux 8virt-develFixedRHSA-2024:435108.07.2024
Red Hat Enterprise Linux 8virtFixedRHSA-2024:435108.07.2024
Red Hat Enterprise Linux 9libvirtFixedRHSA-2024:475723.07.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportlibvirtFixedRHSA-2024:443209.07.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2278616libvirt: stack use-after-free in virNetClientIOEventLoop()

EPSS

Процентиль: 60%
0.00401
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
nvd
больше 1 года назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
msrc
28 дней назад

Описание отсутствует

CVSS3: 6.2
debian
больше 1 года назад

A race condition leading to a stack use-after-free flaw was found in l ...

suse-cvrf
около 1 года назад

Security update for libvirt

EPSS

Процентиль: 60%
0.00401
Низкий

6.2 Medium

CVSS3

Уязвимость CVE-2024-4418