CVE-2024-55884: Critical severity mullvad vpn vulnerability
In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in enable() in exceptionlogging/unix.rs, aka MLLVD-CR-24-01. NOTE: achieving code execution is considered non-trivial.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55884?
CVE-2024-55884 is a vulnerability that can lead to heap-based out-of-bounds writes, potentially affecting the stability of the Mullvad VPN client.
How do I fix CVE-2024-55884?
To fix CVE-2024-55884, update the Mullvad VPN client to the latest version that addresses this vulnerability.
Which versions of Mullvad VPN client are affected by CVE-2024-55884?
CVE-2024-55884 affects Mullvad VPN client versions 2024.6, 2024.8, and 2024.8-beta1.
Can CVE-2024-55884 lead to remote code execution?
While CVE-2024-55884 allows for heap-based out-of-bounds writes, evidence suggests that achieving remote code execution is non-trivial.
What components of the Mullvad VPN client does CVE-2024-55884 impact?
CVE-2024-55884 impacts the exception-handling alternate stack within the enable() function in the exception_logging/unix.rs file.