PT-2024-23806 · Open Networking Foundation · Libfluid

Gabriele Quagliarella

·

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2024-31166

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libfluid version 0.1.0
Description The issue is an Out-of-bounds Read vulnerability in the Open Networking Foundation (ONF) libfluid, specifically in the libfluid msg module. It is associated with the program routine fluid msg::of13::HelloElemVersionBitmap::unpack.
Recommendations For libfluid version 0.1.0, consider disabling the fluid msg::of13::HelloElemVersionBitmap::unpack routine as a temporary workaround until a patch is available.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-31166

Affected Products

Libfluid