A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
CVE ID: CVE-2024-2496
Vendor: , Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product: , Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8 Advanced Virtualization
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 5.55% (scored less or equal to compared to others)
EPSS Date: 2025-05-02 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false