CVE-2024-41660: slpd-lite unauthenticated memory corruption
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41660?
CVE-2024-41660 has a high severity due to the potential for memory overflow issues in the slpd-lite package.
How do I fix CVE-2024-41660?
To fix CVE-2024-41660, update the slpd-lite package to the latest version provided by OpenBMC.
Who is affected by CVE-2024-41660?
Any OpenBMC system that includes the slpd-lite package is affected by CVE-2024-41660.
What does CVE-2024-41660 exploit?
CVE-2024-41660 exploits memory overflow vulnerabilities through malicious slp packets sent to UDP port 427.
Is there a patch available for CVE-2024-41660?
Yes, there is a patch available in the latest release of the slpd-lite package for CVE-2024-41660.