UBUNTU-CVE-2024-1441
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-1441
UBUNTU-CVE-2024-1441
Summary:
Details: An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.
References: https://ubuntu.com/security/CVE-2024-1441, https://access.redhat.com/security/cve/CVE-2024-1441, https://www.cve.org/CVERecord?id=CVE-2024-1441, https://ubuntu.com/security/notices/USN-6734-1, https://ubuntu.com/security/notices/USN-6734-2, https://ubuntu.com/security/notices/USN-8652-1
Affected packages
Package
Name: libvirt
Purl: pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
