Updated libndp packages fix security vulnerabilities
Publication date: 17 Jun 2024Modification date: 17 Jun 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-5564
Description
A vulnerability was found in libndp. This flaw allows a local malicious
user to cause a buffer overflow in NetworkManager, triggered by sending
a malformed IPv6 router advertisement packet. This issue occurred as
libndp was not correctly validating the route length information.
References
SRPMS
9/core
- libndp-1.8-2.1.mga9