CVE-2024-8235

Severity
6.2MEDIUM
EPSS
0.1%
top 72.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30

Description

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

NVDredhat/libvirt10.4.010.7.0
Debianlibvirt< 10.7.0-1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-94ch-6cfh-xxgc: A flaw was found in libvirt2024-08-30
OSV
CVE-2024-8235: A flaw was found in libvirt2024-08-30
CVEList
Libvirt: crash of virtinterfaced via virconnectlistinterfaces()2024-08-30

📋Vendor Advisories

2
Red Hat
libvirt: Crash of virtinterfaced via virConnectListInterfaces()2024-08-29
Debian
CVE-2024-8235: libvirt - A flaw was found in libvirt. A refactor of the code fetching the list of interfa...2024
CVE-2024-8235 (MEDIUM CVSS 6.2) | A flaw was found in libvirt | cvebase.io