ALT-PU-2024-3467-4
Closed vulnerabilities
Published: 2024-04-11
Modified: 2026-01-13
Modified: 2026-01-13
BDU:2024-02834
Уязвимость функции udevListInterfacesByStatus() библиотеки libvirt, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.5)Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: MEDIUM (4.6)Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C
References:
Published: 2024-03-11
Modified: 2026-04-15
Modified: 2026-04-15
CVE-2024-1441
An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.
Severity: MEDIUM (5.5)Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- https://access.redhat.com/errata/RHSA-2024:2560
- https://access.redhat.com/security/cve/CVE-2024-1441
- https://bugzilla.redhat.com/show_bug.cgi?id=2263841
- https://access.redhat.com/errata/RHSA-2024:2560
- https://access.redhat.com/security/cve/CVE-2024-1441
- https://bugzilla.redhat.com/show_bug.cgi?id=2263841
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/45FFKU3LODT345LAB5T4XZA5WKYMXJYU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6MVZO5GXDB7RHY6MS3ZXES3HPK34P3A/
- https://security.netapp.com/advisory/ntap-20250411-0003/
