CVE-2024-2496: Libvirt: null pointer dereference in udevconnectlistallinterfaces()

Description

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

Classification

CVE ID: CVE-2024-2496

Problem Types

NULL Pointer Dereference

Affected Products

Vendor: , Red Hat, Red Hat, Red Hat, Red Hat, Red Hat

Product: , Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8 Advanced Virtualization

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 5.55% (scored less or equal to compared to others)

EPSS Date: 2025-05-02 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-2496
https://access.redhat.com/errata/RHSA-2024:2236
https://access.redhat.com/security/cve/CVE-2024-2496
https://bugzilla.redhat.com/show_bug.cgi?id=2269672

Timeline