UBUNTU-CVE-2024-2496
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-2496
UBUNTU-CVE-2024-2496
Summary:
Details: A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
References: https://ubuntu.com/security/CVE-2024-2496, https://access.redhat.com/security/cve/CVE-2024-2496, https://www.cve.org/CVERecord?id=CVE-2024-2496, https://ubuntu.com/security/notices/USN-6734-1, https://ubuntu.com/security/notices/USN-8652-1
Affected packages
Package
Name: libvirt
Purl: pkg:deb/ubuntu/libvirt?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
