vulnerability

Oracle Linux: CVE-2024-8235: ELSA-2024-9128: libvirt security update (MODERATE)

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:C)
Published
Aug 29, 2024
Added
Nov 21, 2024
Modified
Dec 3, 2025

Description

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.

Solutions

oracle-linux-upgrade-libvirtoracle-linux-upgrade-libvirt-clientoracle-linux-upgrade-libvirt-client-qemuoracle-linux-upgrade-libvirt-daemonoracle-linux-upgrade-libvirt-daemon-commonoracle-linux-upgrade-libvirt-daemon-config-networkoracle-linux-upgrade-libvirt-daemon-config-nwfilteroracle-linux-upgrade-libvirt-daemon-driver-interfaceoracle-linux-upgrade-libvirt-daemon-driver-networkoracle-linux-upgrade-libvirt-daemon-driver-nodedevoracle-linux-upgrade-libvirt-daemon-driver-nwfilteroracle-linux-upgrade-libvirt-daemon-driver-qemuoracle-linux-upgrade-libvirt-daemon-driver-secretoracle-linux-upgrade-libvirt-daemon-driver-storageoracle-linux-upgrade-libvirt-daemon-driver-storage-coreoracle-linux-upgrade-libvirt-daemon-driver-storage-diskoracle-linux-upgrade-libvirt-daemon-driver-storage-iscsioracle-linux-upgrade-libvirt-daemon-driver-storage-logicaloracle-linux-upgrade-libvirt-daemon-driver-storage-mpathoracle-linux-upgrade-libvirt-daemon-driver-storage-rbdoracle-linux-upgrade-libvirt-daemon-driver-storage-scsioracle-linux-upgrade-libvirt-daemon-kvmoracle-linux-upgrade-libvirt-daemon-lockoracle-linux-upgrade-libvirt-daemon-logoracle-linux-upgrade-libvirt-daemon-plugin-lockdoracle-linux-upgrade-libvirt-daemon-plugin-sanlockoracle-linux-upgrade-libvirt-daemon-proxyoracle-linux-upgrade-libvirt-develoracle-linux-upgrade-libvirt-docsoracle-linux-upgrade-libvirt-libsoracle-linux-upgrade-libvirt-nssoracle-linux-upgrade-libvirt-ssh-proxy
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.