Updated libndp packages fix security vulnerabilities
Publication date: 17 Jun 2024Modification date: 17 Jun 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-5564
Description
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
References
SRPMS
9/core
- libndp-1.8-2.1.mga9