PT-2024-4010 · Libvirt+9 · Libvirt+9

Martin Širokov

·

Published

2024-05-02

·

Updated

2026-02-25

·

CVE-2024-4418

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libvirt (affected versions not specified)
Description: A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the data pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being freed when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2024:4351
ALSA-2024:4757
ALT-PU-2024-13761
ALT-PU-2024-14221
AZL-40396
AZL-40447
BDU:2024-04436
CESA-2024_4351
CVE-2024-4418
INFSA-2024_4351
INFSA-2024_4757
OESA-2024-1683
OESA-2024-1743
OPENSUSE-SU-2024:13948-1
OPENSUSE-SU-2024_1962-1
RHSA-2024:4351
RHSA-2024:4432
RHSA-2024:4757
RHSA-2024_4351
RHSA-2024_4757
RLSA-2024:4351
SUSE-SU-2024:1962-1
SUSE-SU-2024_1962-1
SUSE-SU-2025:20012-1
USN-6763-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libvirt