CVE-2024-2494
published 2024-03-21CVE-2024-2494: A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is…
PriorityP422medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.36%
28.7th percentile
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 9.0.0-4+deb12u1 (bookworm) | libvirt 9.0.0-4+deb12u1 (bookworm) |
| msrc | azl3_libvirt_10.0.0-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libvirt_7.10.0-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libvirt_7.10.0-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | libvirt | >= 0 < 7.0.0-3+deb11u3 | 7.0.0-3+deb11u3 |
| redhat | libvirt | >= 0 < 9.0.0-4+deb12u1 | 9.0.0-4+deb12u1 |
| redhat | libvirt | >= 0 < 10.2.0-1 | 10.2.0-1 |
| redhat | libvirt | >= 0 < 10.2.0-1 | 10.2.0-1 |
| redhat | libvirt | >= 0 < 6.0.0-0ubuntu8.19 | 6.0.0-0ubuntu8.19 |
| redhat | libvirt | >= 0 < 8.0.0-1ubuntu7.10 | 8.0.0-1ubuntu7.10 |
| redhat | libvirt | >= 0 < 10.0.0-2ubuntu8.1 | 10.0.0-2ubuntu8.1 |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_msrc6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2024-04-29·CVSS 5.5
CVE-2024-2494 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
USN-6734-1 fixed vulnerabilities in libvirt. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Alexander Kuznetsov discovered that libvirt incorrectly handled certain API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain RPC library API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-2494)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2024-04-15·CVSS 5.5
CVE-2024-1441 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Alexander Kuznetsov discovered that libvirt incorrectly handled certain API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain RPC library API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-2494)
It was discovered that libvirt incorrectly handled detaching certain host
interfaces. An attacker could possibly use this issue to cause libvirt to
crash, resulting in a denial of service. (CVE-2024-2496)
Instructions: After a standard system update you need to reboot your computer to make all
the necess
Red Hat
libvirt: negative g_new0 length can lead to unbounded memory allocation
vendor_redhat·2024-03-21·CVSS 6.2
CVE-2024-2494 [MEDIUM] CWE-789 libvirt: negative g_new0 length can lead to unbounded memory allocation
libvirt: negative g_new0 length can lead to unbounded memory allocation
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the n
Microsoft
Libvirt: negative g_new0 length can lead to unbounded memory allocation
vendor_msrc·2024-03-12·CVSS 6.2
CVE-2024-2494 [MEDIUM] CWE-789 Libvirt: negative g_new0 length can lead to unbounded memory allocation
Libvirt: negative g_new0 length can lead to unbounded memory allocation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refere
Debian
CVE-2024-2494: libvirt - A flaw was found in the RPC library APIs of libvirt. The RPC server deserializat...
vendor_debian·2024·CVSS 6.2
CVE-2024-2494 [MEDIUM] CVE-2024-2494: libvirt - A flaw was found in the RPC library APIs of libvirt. The RPC server deserializat...
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
Scope: local
bookworm: resolved (fixed in 9.0.0-4+deb12u1)
bullseye: resolved (fixed in 7.0.0-3+deb11u3)
forky: resolved (fixed in 10.2.0-1)
sid: resolved (fixed in 10.2.0-1)
trixie: resolved (fixed in 10.2.0-1)
OSV
libvirt vulnerabilities
osv·2024-04-29·CVSS 5.5
CVE-2024-1441 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
USN-6734-1 fixed vulnerabilities in libvirt. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Alexander Kuznetsov discovered that libvirt incorrectly handled certain API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain RPC library API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-2494)
OSV
libvirt vulnerabilities
osv·2024-04-15·CVSS 5.5
CVE-2024-1441 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
Alexander Kuznetsov discovered that libvirt incorrectly handled certain API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-1441)
It was discovered that libvirt incorrectly handled certain RPC library API
calls. An attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. (CVE-2024-2494)
It was discovered that libvirt incorrectly handled detaching certain host
interfaces. An attacker could possibly use this issue to cause libvirt to
crash, resulting in a denial of service. (CVE-2024-2496)
GHSA
GHSA-h9fq-4hj4-g596: A flaw was found in the RPC library APIs of libvirt
ghsa_unreviewed·2024-03-21
CVE-2024-2494 [MEDIUM] CWE-789 GHSA-h9fq-4hj4-g596: A flaw was found in the RPC library APIs of libvirt
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
OSV
CVE-2024-2494: A flaw was found in the RPC library APIs of libvirt
osv·2024-03-21·CVSS 6.2
CVE-2024-2494 [MEDIUM] CVE-2024-2494: A flaw was found in the RPC library APIs of libvirt
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:2560https://access.redhat.com/errata/RHSA-2024:3253https://access.redhat.com/security/cve/CVE-2024-2494https://bugzilla.redhat.com/show_bug.cgi?id=2270115https://lists.libvirt.org/archives/list/[email protected]/thread/BKRQXPLPC6B7FLHJXSBQYW7HNDEBW6RJ/https://access.redhat.com/errata/RHSA-2024:2560https://access.redhat.com/errata/RHSA-2024:3253https://access.redhat.com/security/cve/CVE-2024-2494https://bugzilla.redhat.com/show_bug.cgi?id=2270115https://lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlhttps://lists.libvirt.org/archives/list/[email protected]/thread/BKRQXPLPC6B7FLHJXSBQYW7HNDEBW6RJ/https://security.netapp.com/advisory/ntap-20240517-0009/
2024-03-21
Published