NULL pointer dereference in libvirt - CVE-2024-8235
Published: November 12, 2024
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in interface/interface_backend_udev.c when virConnectListInterfaces() is called requesting 0 netowrks to be filled. A local user can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
libvirt (Red Hat package)
How to mitigate CVE-2024-8235
libvirt (Red Hat package) - update to 10.5.0-7.el9_5