
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2024-2494) was discovered in the RPC library APIs of libvirt, disclosed on March 21, 2024. The flaw exists in the RPC server deserialization code where memory allocation for arrays occurs before non-negative length checks are performed by the C API entry points (NVD).
The vulnerability occurs when passing a negative length to the g_new0 function, which results in a crash due to the negative length being treated as a huge positive number. The issue was found and diagnosed by ALT Linux Team using AFLplusplus. The vulnerability has been assigned a CVSS v3.1 base score of 6.2 (MEDIUM) with the vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (Red Hat).
When successfully exploited, this vulnerability allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash (NVD).
The vulnerability requires local access and can be exploited by an unprivileged user. No user interaction is needed for exploitation. The vulnerability has been confirmed to be exploitable in real-world conditions (Red Hat).
The vulnerability has been fixed in upstream libvirt with commit 8a3f8d957507c1f8223fdcf25a3ff885b15557f2. Red Hat has released security updates through RHSA-2024:2560 for RHEL 9 and RHSA-2024:3253 for RHEL 8. Users are advised to update their libvirt packages to the patched versions (Libvirt List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."