CVE-2024-5564

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
Configurations

No configuration.

History

16 Sep 2024, 21:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00011.html', 'source': 'secalert@redhat.com'}

19 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4642 -

18 Jul 2024, 22:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4636 -
  • () https://access.redhat.com/errata/RHSA-2024:4640 -
  • () https://access.redhat.com/errata/RHSA-2024:4641 -
  • () https://access.redhat.com/errata/RHSA-2024:4643 -

18 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4618 -
  • () https://access.redhat.com/errata/RHSA-2024:4619 -
  • () https://access.redhat.com/errata/RHSA-2024:4620 -
  • () https://access.redhat.com/errata/RHSA-2024:4622 -

28 Jun 2024, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.4
v2 : unknown
v3 : 8.1

19 Jun 2024, 20:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00011.html -

03 Jun 2024, 14:46

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en libndp. Esta falla permite que un usuario malintencionado local provoque un desbordamiento del búfer en NetworkManager, provocado al enviar un paquete de publicidad de enrutador IPv6 con formato incorrecto. Este problema se produjo porque libndp no validaba correctamente la información de longitud de la ruta.

31 May 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 19:15

Updated : 2024-09-16 21:15


NVD link : CVE-2024-5564

Mitre link : CVE-2024-5564

CVE.ORG link : CVE-2024-5564


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')