Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2024-4418

около 2 лет назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2024-4418

около 2 лет назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2024-4418

около 2 лет назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
EPSS: Низкий
msrc логотип

CVE-2024-4418

12 месяцев назад

Libvirt: stack use-after-free in virnetclientioeventloop()

CVSS3: 6.2
EPSS: Низкий
debian логотип

CVE-2024-4418

около 2 лет назад

A race condition leading to a stack use-after-free flaw was found in l ...

CVSS3: 6.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1962-1

около 2 лет назад

Security update for libvirt

EPSS: Низкий
rocky логотип

RLSA-2024:4351

почти 2 года назад

Low: virt:rhel and virt-devel:rhel security and bug fix update

EPSS: Низкий
github логотип

GHSA-q262-3hfr-f5q4

около 2 лет назад

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
EPSS: Низкий
oracle-oval логотип

ELSA-2024-4757

почти 2 года назад

ELSA-2024-4757: libvirt security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4351

почти 2 года назад

ELSA-2024-4351: virt:ol and virt-devel:ol security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12673

почти 2 года назад

ELSA-2024-12673: libvirt security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-04436

около 2 лет назад

Уязвимость метода virNetClientIOEventLoop() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю получить несанкционированный доступ к virtproxyd без аутентификации

CVSS3: 6.2
EPSS: Низкий
redos логотип

ROS-20240607-04

около 2 лет назад

Уязвимость libvirt

CVSS3: 6.2
EPSS: Низкий
oracle-oval логотип

ELSA-2024-12604

почти 2 года назад

ELSA-2024-12604: virt:kvm_utils3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12605

почти 2 года назад

ELSA-2024-12605: virt:kvm_utils2 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-4418

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-4418

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-4418

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-4418

Libvirt: stack use-after-free in virnetclientioeventloop()

CVSS3: 6.2
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-4418

A race condition leading to a stack use-after-free flaw was found in l ...

CVSS3: 6.2
0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1962-1

Security update for libvirt

0%
Низкий
около 2 лет назад
rocky логотип
RLSA-2024:4351

Low: virt:rhel and virt-devel:rhel security and bug fix update

0%
Низкий
почти 2 года назад
github логотип
GHSA-q262-3hfr-f5q4

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2024-4757

ELSA-2024-4757: libvirt security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-4351

ELSA-2024-4351: virt:ol and virt-devel:ol security and bug fix update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-12673

ELSA-2024-12673: libvirt security update (IMPORTANT)

почти 2 года назад
fstec логотип
BDU:2024-04436

Уязвимость метода virNetClientIOEventLoop() библиотеки управления виртуализацией Libvirt, позволяющая нарушителю получить несанкционированный доступ к virtproxyd без аутентификации

CVSS3: 6.2
0%
Низкий
около 2 лет назад
redos логотип
ROS-20240607-04

Уязвимость libvirt

CVSS3: 6.2
0%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2024-12604

ELSA-2024-12604: virt:kvm_utils3 security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2024-12605

ELSA-2024-12605: virt:kvm_utils2 security update (IMPORTANT)

почти 2 года назад

Уязвимостей на страницу