CVE-2024-2496: Libvirt: null pointer dereference in udevconnectlistallinterfaces()
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
Other sources
A NULL pointer dereference issue was found in libvirt in the udevConnectListAllInterfaces() function. It could occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API.
Upstream fix: https://gitlab.com/libvirt/libvirt/-/commit/2ca94317ac642a70921947150ced8acc674ccdc8
— Red Hat
Libvirt: null pointer dereference in udevconnectlistallinterfaces()
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2496?
CVE-2024-2496 is classified as a moderate severity vulnerability due to the potential for exploitation through NULL pointer dereference.
How do I fix CVE-2024-2496?
To fix CVE-2024-2496, upgrade to the affected libvirt versions listed as 6.0.0-0ubuntu8.19, 8.0.0-1ubuntu7.10, 9.6.0-1ubuntu1.1, or 9.8.0-1.
Which systems are affected by CVE-2024-2496?
CVE-2024-2496 affects specific versions of libvirt on Ubuntu, RedHat, and Debian systems.
What can happen if CVE-2024-2496 is exploited?
Exploitation of CVE-2024-2496 can lead to potential denial of service conditions by causing application crashes.
Is there a specific Mitigation for CVE-2024-2496?
The recommended mitigation for CVE-2024-2496 is to ensure that the affected versions of libvirt are updated immediately.