Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8235

Опубликовано: 29 авг. 2024
Источник: redhat
CVSS3: 6.2

Описание

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

Отчет

This bug was introduced in libvirt-10.4.0. All versions of libvirt as shipped in Red Hat Enterprise Linux prior to RHEL-9.5 are unaffected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libvirtAffected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8virt:rhel/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtNot affected
Red Hat Enterprise Linux 9libvirtFixedRHSA-2024:912812.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2308680libvirt: Crash of virtinterfaced via virConnectListInterfaces()

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

CVSS3: 6.2
nvd
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

CVSS3: 6.2
debian
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list ...

CVSS3: 6.2
redos
11 месяцев назад

Уязвимость libvirt

CVSS3: 6.2
github
12 месяцев назад

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

6.2 Medium

CVSS3