CVE-2024-0217: Packagekitd: use-after-free in idle function callback

Published Jan 3, 2024
·
Updated

A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.

Other sources

PackageKit relies on “transactions” as a work unit to wrap package manager actions, these transactions are created by the user and freed when no longer in use or when a terminal error is emitted. It was observed that under some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory accesses could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost. Usage of memory after it is cleaned is named Use-After-Free (UAF). The most reliable way a transaction can be made to be cleaned whilst still running is by having a task for a package backend (dnf in our case) and simultaneously causing an error or successful termination of another task for that same transaction.

Red Hat

Affected Software

5 affected componentsFixes available
redhat/PackageKit<1.2.7
1.2.7
Packagekit Project Packagekit<1.2.7
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Fedoraproject Fedora=39

Event History

Jan 3, 2024
Data Sourced
via Red Hat·01:18 PM
DescriptionSeverityAffected Software
CVE Published
05:04 PM
Data Sourced
05:04 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-0217?

CVE-2024-0217 is classified with a high severity due to the potential for exploitation through use-after-free vulnerabilities.

2

How do I fix CVE-2024-0217?

To address CVE-2024-0217, update PackageKit to version 1.2.7 or later.

3

Which systems are affected by CVE-2024-0217?

CVE-2024-0217 affects PackageKit versions prior to 1.2.7 on Red Hat Enterprise Linux 8.0, 9.0, and Fedora 39.

4

What is a use-after-free vulnerability as seen in CVE-2024-0217?

A use-after-free vulnerability occurs when memory is accessed after it has been freed, potentially leading to unpredictable behavior or crashes.

5

Can CVE-2024-0217 be exploited remotely?

Yes, CVE-2024-0217 could potentially be exploited remotely if an attacker can manipulate transactions within the affected PackageKit service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203