Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2024-0217: SUSE Linux Security Advisory

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

SUSE: CVE-2024-0217: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/03/2024
Created
03/23/2024
Added
03/22/2024
Modified
04/12/2024

Description

A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.

Solution(s)

  • suse-upgrade-libpackagekit-glib2-18
  • suse-upgrade-libpackagekit-glib2-18-32bit
  • suse-upgrade-libpackagekit-glib2-devel
  • suse-upgrade-libpackagekit-glib2-devel-32bit
  • suse-upgrade-libyui-devel
  • suse-upgrade-libyui-ncurses-devel
  • suse-upgrade-libyui-ncurses-pkg-devel
  • suse-upgrade-libyui-ncurses-pkg11
  • suse-upgrade-libyui-ncurses-pkg15
  • suse-upgrade-libyui-ncurses-rest-api-devel
  • suse-upgrade-libyui-ncurses-rest-api15
  • suse-upgrade-libyui-ncurses-tools
  • suse-upgrade-libyui-ncurses15
  • suse-upgrade-libyui-qt-devel
  • suse-upgrade-libyui-qt-graph-devel
  • suse-upgrade-libyui-qt-graph15
  • suse-upgrade-libyui-qt-pkg-devel
  • suse-upgrade-libyui-qt-pkg11
  • suse-upgrade-libyui-qt-pkg15
  • suse-upgrade-libyui-qt-rest-api-devel
  • suse-upgrade-libyui-qt-rest-api15
  • suse-upgrade-libyui-qt15
  • suse-upgrade-libyui-rest-api-devel
  • suse-upgrade-libyui-rest-api11
  • suse-upgrade-libyui-rest-api15
  • suse-upgrade-libyui11
  • suse-upgrade-libyui15
  • suse-upgrade-libzypp
  • suse-upgrade-libzypp-devel
  • suse-upgrade-packagekit
  • suse-upgrade-packagekit-backend-dnf
  • suse-upgrade-packagekit-backend-zypp
  • suse-upgrade-packagekit-branding-sle
  • suse-upgrade-packagekit-branding-upstream
  • suse-upgrade-packagekit-devel
  • suse-upgrade-packagekit-gstreamer-plugin
  • suse-upgrade-packagekit-gtk3-module
  • suse-upgrade-packagekit-lang
  • suse-upgrade-typelib-1_0-packagekitglib-1_0
  • suse-upgrade-yast2-pkg-bindings
  • suse-upgrade-zypper
  • suse-upgrade-zypper-log
  • suse-upgrade-zypper-needs-restarting

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;