CVE-2024-5564: Red Hat Enterprise Linux 10
High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:1.9-2.el10 (fixed in 0:1.9-2.el10)
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.2-10.el7_9 (fixed in 0:1.2-10.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 0:1.7-7.el8_10 (fixed in 0:1.7-7.el8_10)
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:1.7-4.el8_2 (fixed in 0:1.7-4.el8_2)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:1.7-6.el8_4 (fixed in 0:1.7-6.el8_4)
- Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 0:1.7-6.el8_4 (fixed in 0:1.7-6.el8_4)
- Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 0:1.7-6.el8_4 (fixed in 0:1.7-6.el8_4)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:1.7-7.el8_6 (fixed in 0:1.7-7.el8_6)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:1.7-7.el8_6 (fixed in 0:1.7-7.el8_6)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:1.7-7.el8_6 (fixed in 0:1.7-7.el8_6)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 0:1.7-7.el8_8 (fixed in 0:1.7-7.el8_8)
- Red Hat Red Hat Enterprise Linux 9: before 0:1.8-6.el9_4 (fixed in 0:1.8-6.el9_4)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:1.8-5.el9_0 (fixed in 0:1.8-5.el9_0)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:1.8-5.el9_2 (fixed in 0:1.8-5.el9_2)
Published 2024-05-31. Last modified 2026-06-17.