Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-1441

Published: March 12, 2024Last modified: June 5, 2025

Description

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Notes

Fixed in v10.1.0: https://gitlab.com/libvirt/libvirt/-/commit/c664015fe3a7bf59db26686e9ed69af011c6ebb8

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibvirtVulnerable (8.9.0-r4)
StreamlibvirtFixed (10.1.0-r0)

References

ON THIS PAGE