CVE-2024-1441: Libvirt: off-by-one error in udevlistinterfacesbystatus()

Published Feb 12, 2024
·
Updated

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the names array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

Other sources

An off-by-one error was found in libvirt in the udevListInterfacesByStatus() function when the number of interfaces exceeds nameslen. The issue can be reproduced by sending a specially crafted entry to the libvirt daemon and can lead to a segmentation fault. An unprivileged user could use this flaw to cause a denial of service condition.

Red Hat

Libvirt: off-by-one error in udevlistinterfacesbystatus()

Microsoft

Affected Software

8 affected componentsFixes available
ubuntu/libvirt<6.0.0-0ubuntu8.19
6.0.0-0ubuntu8.19
ubuntu/libvirt<8.0.0-1ubuntu7.10
8.0.0-1ubuntu7.10
ubuntu/libvirt<9.6.0-1ubuntu1.1
9.6.0-1ubuntu1.1
debian/libvirt<=5.0.0-4+deb10u1, <=7.0.0-3+deb11u2, <=9.0.0-4, <=10.0.0-2
5.0.0-4+deb10u210.2.0-1
redhat/libvirt<10.1.0
10.1.0
Microsoft azl3 libvirt 10.0.0-5
Microsoft cbl2 libvirt 7.10.0-10
Microsoft cbl2 libvirt 7.10.0-8

Event History

Mar 11, 2024
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Apr 15, 2024
Data Sourced
via Launchpad·05:59 PM
Description
Jun 30, 2024
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
SeverityAffected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverity

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2024-1441?

CVE-2024-1441 has a medium severity rating due to its potential to be exploited by unprivileged clients.

2

How do I fix CVE-2024-1441?

To fix CVE-2024-1441, update the libvirt package to version 10.1.0 for Red Hat, 6.0.0-0ubuntu8.19 for focal, 8.0.0-1ubuntu7.10 for jammy, or 9.6.0-1ubuntu1.1 for mantic.

3

What causes CVE-2024-1441?

CVE-2024-1441 is caused by an off-by-one error in the udevListInterfacesByStatus() function of libvirt when handling a number of interfaces that exceeds the size of the names array.

4

Which versions of libvirt are affected by CVE-2024-1441?

Affected versions of libvirt include versions prior to 10.1.0 for Red Hat, and several specific Ubuntu and Debian versions listed in the vulnerability report.

5

Can CVE-2024-1441 be exploited remotely?

Yes, CVE-2024-1441 can be exploited remotely by sending specially crafted data to the libvirt daemon.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203