PT-2024-23804 · Open Networking Foundation · Libfluid

Gabriele Quagliarella

·

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2024-31164

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libfluid version 0.1.0
Description The issue is related to an Unchecked Return Value to NULL Pointer Dereference vulnerability in the Open Networking Foundation (ONF) libfluid, specifically in the libfluid msg module. This vulnerability is associated with program routines fluid msg::ActionList::unpack13.
Recommendations For libfluid version 0.1.0, as a temporary workaround, consider disabling the fluid msg::ActionList::unpack13 routine until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2024-31164

Affected Products

Libfluid