CVE-2024-7409: Red Hat Enterprise Linux 10

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240905091210.489197e6 (fixed in 8100020240905091210.489197e6)
  • Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
  • Red Hat Red Hat Enterprise Linux 9: before 17:9.0.0-10.el9_5 (fixed in 17:9.0.0-10.el9_5)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 17:7.2.0-14.el9_2.14 (fixed in 17:7.2.0-14.el9_2.14)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 17:8.2.0-11.el9_4.8 (fixed in 17:8.2.0-11.el9_4.8)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202411212100-0 (fixed in 413.92.202411212100-0); before 413.92.202409180051-0 (fixed in 413.92.202409180051-0)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202411130444-0 (fixed in 414.92.202411130444-0)
  • Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202409162258-0 (fixed in 415.92.202409162258-0); before 415.92.202411050056-0 (fixed in 415.92.202411050056-0)
  • Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202411261619-0 (fixed in 416.94.202411261619-0)
  • Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202411261220-0 (fixed in 417.94.202411261220-0)

Published 2024-08-05. Last modified 2026-10-09.