CVE-2024-2494
Rocky Linux vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2024-2494) was discovered in the RPC library APIs of libvirt, disclosed on March 21, 2024. The flaw exists in the RPC server deserialization code where memory allocation for arrays occurs before non-negative length checks are performed by the C API entry points (NVD).

Technical details

The vulnerability occurs when passing a negative length to the g_new0 function, which results in a crash due to the negative length being treated as a huge positive number. The issue was found and diagnosed by ALT Linux Team using AFLplusplus. The vulnerability has been assigned a CVSS v3.1 base score of 6.2 (MEDIUM) with the vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Impact

When successfully exploited, this vulnerability allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash (NVD).

Exploitability

The vulnerability requires local access and can be exploited by an unprivileged user. No user interaction is needed for exploitation. The vulnerability has been confirmed to be exploitable in real-world conditions (Red Hat).

Mitigation and workarounds

The vulnerability has been fixed in upstream libvirt with commit 8a3f8d957507c1f8223fdcf25a3ff885b15557f2. Red Hat has released security updates through RHSA-2024:2560 for RHEL 9 and RHSA-2024:3253 for RHEL 8. Users are advised to update their libvirt packages to the patched versions (Libvirt List).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64561HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 04, 2026
CVE-2026-7867HIGH7.8
  • Rocky Linux logoRocky Linux
  • udisks2-debugsource
NoYesAug 06, 2026
CVE-2026-5056HIGH7.8
  • Rocky Linux logoRocky Linux
  • mingw32-gstreamer1-plugins-good-debuginfo
NoYesJul 29, 2026
CVE-2026-18649HIGH7.5
  • Rocky Linux logoRocky Linux
  • gstreamer1-plugins-good-gtk
NoYesAug 06, 2026
CVE-2026-69152HIGH7.5
  • JavaScript logoJavaScript
  • grafana-elasticsearch
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management