CVE-2024-2494: Red Hat Enterprise Linux 6
Medium severity, CVSS 6.2. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.
Affected products
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 8100020240409073027.489197e6 (fixed in 8100020240409073027.489197e6)
- Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
- Red Hat Red Hat Enterprise Linux 9: before 0:10.0.0-6.2.el9_4 (fixed in 0:10.0.0-6.2.el9_4)
Published 2024-03-21. Last modified 2026-06-17.