Untriaged
Permalink
CVE-2024-31420
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Cnv: dos through repeatedly calling vm-dump-metrics until virt handler crashes
A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.
References
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- RHBZ#2272951 issue-tracking x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry x_transferred
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2272951 issue-tracking x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2272951 issue-tracking x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2272951 issue-tracking x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry
- RHBZ#2272951 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-31420 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2272951 issue-tracking x_refsource_REDHAT x_transferred
Affected products
cnv
- ==4.15.0
- ==4.15.0
kubevirt
Package maintainers
-
@haslersn Sebastian Hasler <haslersn@fius.informatik.uni-stuttgart.de>