Database/Kernel, userspace & hypervisor

libvirt: Off-by-one in udevListInterfacesByStatus() - libvirtd crash / info leak
CVSS 5.5CVE-2024-1441Kernel, userspace & hypervisorcurated
Impact
Off-by-one in udevListInterfacesByStatus() - libvirtd crash / info leak
Who can reach it
Local user or API client with libvirt access
What to do
Package update + libvirtd restart; running domains survive
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd): An out-of-bounds access in the amdkfd (KFD compute driverCVE-2024-26817 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd)Medium
- Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/instmem): Concurrent GPU work races the instance-memory pointerCVE-2024-26984 · Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/instmem)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2024-26986 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabledCVE-2024-27437 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/gpu/drm/nouveau): Calling the legacy pushbuf submission ioctl on a client that has VM_BINDCVE-2024-35786 · Linux kernel (drivers/gpu/drm/nouveau)Medium
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistCVE-2024-35841 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.