Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-2494

Опубликовано: 21 мар. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.2

Описание

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

РелизСтатусПримечание
devel

released

10.0.0-2ubuntu8.1
esm-infra-legacy/trusty

released

1.2.2-0ubuntu13.1.28+esm2
esm-infra-legacy/xenial

released

1.3.1-1ubuntu10.31+esm1
esm-infra/bionic

released

4.0.0-1ubuntu8.21+esm1
esm-infra/focal

released

6.0.0-0ubuntu8.19
esm-infra/xenial

ignored

end of ESM support, was needs-triage
focal

released

6.0.0-0ubuntu8.19
jammy

released

8.0.0-1ubuntu7.10
mantic

released

9.6.0-1ubuntu1.1
noble

released

10.0.0-2ubuntu8.1

Показывать по

EPSS

Процентиль: 28%
0.00367
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
redhat
больше 2 лет назад

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 6.2
nvd
больше 2 лет назад

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 6.2
msrc
больше 2 лет назад

Libvirt: negative g_new0 length can lead to unbounded memory allocation

CVSS3: 6.2
debian
больше 2 лет назад

A flaw was found in the RPC library APIs of libvirt. The RPC server de ...

suse-cvrf
больше 2 лет назад

Security update for libvirt

EPSS

Процентиль: 28%
0.00367
Низкий

6.2 Medium

CVSS3