Resource exhaustion in NetworkManager - CVE-2024-6501
Published: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled. A remote attacker can send a malformed LLDP packet to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
OpenShift API for Data Protection (OADP)
NetworkManager
NetworkManager-bluetooth
NetworkManager-cloud-setup
NetworkManager-debuginfo
NetworkManager-debugsource
NetworkManager-libnm
NetworkManager-libnm-devel
NetworkManager-ppp
NetworkManager-team
NetworkManager-wifi
NetworkManager-wwan
NetworkManager-config-server
NetworkManager-help
NetworkManager (Red Hat package)
How to mitigate CVE-2024-6501
NetworkManager - update to 1.44.2-3
NetworkManager-bluetooth - update to 1.44.2-3
NetworkManager-cloud-setup - update to 1.44.2-3
NetworkManager-debuginfo - update to 1.44.2-3
NetworkManager-debugsource - update to 1.44.2-3
NetworkManager-libnm - update to 1.44.2-3
NetworkManager-libnm-devel - update to 1.44.2-3
NetworkManager-ppp - update to 1.44.2-3
NetworkManager-team - update to 1.44.2-3
NetworkManager-wifi - update to 1.44.2-3
NetworkManager-wwan - update to 1.44.2-3
NetworkManager-config-server - update to 1.44.2-3
NetworkManager-help - update to 1.44.2-3
NetworkManager (Red Hat package) - update to 1.48.10-2.el9_5