CVE-2024-1441: Red Hat Enterprise Linux 6
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.
Affected products
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
- Red Hat Red Hat Enterprise Linux 9: before 0:10.0.0-6.2.el9_4 (fixed in 0:10.0.0-6.2.el9_4)
Published 2024-03-11. Last modified 2026-06-17.