Advisories ยป MGASA-2024-0225

Updated libndp packages fix security vulnerabilities

Publication date: 17 Jun 2024
Modification date: 17 Jun 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-5564

Description

A vulnerability was found in libndp. This flaw allows a local malicious
user to cause a buffer overflow in NetworkManager, triggered by sending
a malformed IPv6 router advertisement packet. This issue occurred as
libndp was not correctly validating the route length information.
                

References

SRPMS

9/core