MGASA-2024-0225 - Updated libndp packages fix security vulnerabilities

Publication date: 17 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0225.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-5564

A vulnerability was found in libndp. This flaw allows a local malicious
user to cause a buffer overflow in NetworkManager, triggered by sending
a malformed IPv6 router advertisement packet. This issue occurred as
libndp was not correctly validating the route length information.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33304
- https://ubuntu.com/security/notices/USN-6830-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5564

SRPMS:
- 9/core/libndp-1.8-2.1.mga9

Mageia 2024-0225: libndp Security Advisory Updates

A vulnerability was found in libndp

Summary

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

References

- https://bugs.mageia.org/show_bug.cgi?id=33304

- https://ubuntu.com/security/notices/USN-6830-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5564

Resolution

MGASA-2024-0225 - Updated libndp packages fix security vulnerabilities

SRPMS

- 9/core/libndp-1.8-2.1.mga9

Severity
Publication date: 17 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0225.html
Type: security
CVE: CVE-2024-5564

Related News