CVE-2024-2494: Red Hat Enterprise Linux 6

Medium severity, CVSS 6.2. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

Affected products

  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240409073027.489197e6 (fixed in 8100020240409073027.489197e6)
  • Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
  • Red Hat Red Hat Enterprise Linux 9: before 0:10.0.0-6.2.el9_4 (fixed in 0:10.0.0-6.2.el9_4)

Published 2024-03-21. Last modified 2026-06-17.