{"id":"USN-6734-1","summary":"libvirt vulnerabilities","details":"Alexander Kuznetsov discovered that libvirt incorrectly handled certain API\ncalls. An attacker could possibly use this issue to cause libvirt to crash,\nresulting in a denial of service. (CVE-2024-1441)\n\nIt was discovered that libvirt incorrectly handled certain RPC library API\ncalls. An attacker could possibly use this issue to cause libvirt to crash,\nresulting in a denial of service. (CVE-2024-2494)\n\nIt was discovered that libvirt incorrectly handled detaching certain host\ninterfaces. An attacker could possibly use this issue to cause libvirt to\ncrash, resulting in a denial of service. (CVE-2024-2496)\n","modified":"2026-02-10T04:43:40Z","published":"2024-04-15T16:44:00Z","related":["UBUNTU-CVE-2024-1441","UBUNTU-CVE-2024-2494","UBUNTU-CVE-2024-2496"],"upstream":["CVE-2024-1441","CVE-2024-2494","CVE-2024-2496","UBUNTU-CVE-2024-1441","UBUNTU-CVE-2024-2494","UBUNTU-CVE-2024-2496"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6734-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-1441"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-2494"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-2496"}],"affected":[{"package":{"name":"libvirt","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libvirt@6.0.0-0ubuntu8.19?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.0-0ubuntu8.19"}]}],"versions":["5.4.0-0ubuntu5","6.0.0-0ubuntu1","6.0.0-0ubuntu2","6.0.0-0ubuntu3","6.0.0-0ubuntu4","6.0.0-0ubuntu5","6.0.0-0ubuntu6","6.0.0-0ubuntu7","6.0.0-0ubuntu8","6.0.0-0ubuntu8.1","6.0.0-0ubuntu8.2","6.0.0-0ubuntu8.3","6.0.0-0ubuntu8.4","6.0.0-0ubuntu8.5","6.0.0-0ubuntu8.7","6.0.0-0ubuntu8.8","6.0.0-0ubuntu8.9","6.0.0-0ubuntu8.10","6.0.0-0ubuntu8.11","6.0.0-0ubuntu8.12","6.0.0-0ubuntu8.13","6.0.0-0ubuntu8.14","6.0.0-0ubuntu8.15","6.0.0-0ubuntu8.16"],"ecosystem_specific":{"binaries":[{"binary_name":"libnss-libvirt","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-clients","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-lxc","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-qemu","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-storage-gluster","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-storage-rbd","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-storage-zfs","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-vbox","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-driver-xen","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-system","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-system-systemd","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-daemon-system-sysv","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-dev","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-sanlock","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt-wireshark","binary_version":"6.0.0-0ubuntu8.19"},{"binary_name":"libvirt0","binary_version":"6.0.0-0ubuntu8.19"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6734-1.json","cves_map":{"ecosystem":"Ubuntu:20.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-1441"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-2494"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-2496"}]}}},{"package":{"name":"libvirt","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libvirt@8.0.0-1ubuntu7.10?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.0-1ubuntu7.10"}]}],"versions":["7.6.0-0ubuntu1","7.6.0-0ubuntu3","8.0.0-1ubuntu3","8.0.0-1ubuntu4","8.0.0-1ubuntu5","8.0.0-1ubuntu6","8.0.0-1ubuntu7","8.0.0-1ubuntu7.1","8.0.0-1ubuntu7.2","8.0.0-1ubuntu7.3","8.0.0-1ubuntu7.4","8.0.0-1ubuntu7.5","8.0.0-1ubuntu7.6","8.0.0-1ubuntu7.7","8.0.0-1ubuntu7.8","8.0.0-1ubuntu7.9"],"ecosystem_specific":{"binaries":[{"binary_name":"libnss-libvirt","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-clients","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-config-network","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-config-nwfilter","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-lxc","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-qemu","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-storage-gluster","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-storage-iscsi-direct","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-storage-rbd","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-storage-zfs","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-vbox","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-driver-xen","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-system","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-system-systemd","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-daemon-system-sysv","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-dev","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-login-shell","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-sanlock","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt-wireshark","binary_version":"8.0.0-1ubuntu7.10"},{"binary_name":"libvirt0","binary_version":"8.0.0-1ubuntu7.10"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6734-1.json","cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-1441"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-2494"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-2496"}]}}}],"schema_version":"1.7.3"}