CVE-2024-1929: Local Root Exploit via Configuration Dictionary
Published Mar 4, 2024
·Updated
Local Root Exploit via Configuration Dictionary
Affected Software
4 affected componentsFixes available
dnf5 dnf5daemon-server<5.1.17
RPM dnf5<5.1.17
Microsoft azl3 dnf5 5.1.11-2
Microsoft azl3 dnf5 5.1.11-3
Event History
May 8, 2024
CVE Published
via MITRE·01:53 AM
Data Sourced
via MITRE·01:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:30 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:30 AM
Affected Software
Updated
via Microsoft·02:30 AM
SeverityAffected Software
Updated
via Microsoft·02:30 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-1929?
CVE-2024-1929 is classified as a high severity vulnerability due to its potential impact on confidentiality and integrity.
2
How do I fix CVE-2024-1929?
To fix CVE-2024-1929, you should update dnf5daemon-server to version 5.1.17 or later.
3
What software is affected by CVE-2024-1929?
CVE-2024-1929 affects dnf5daemon-server versions prior to 5.1.17.
4
What type of vulnerability is CVE-2024-1929?
CVE-2024-1929 is a local root exploit via the Configuration Dictionary in dnf5daemon-server.
5
Can CVE-2024-1929 be exploited remotely?
CVE-2024-1929 requires local access to exploit, so it is not a remote vulnerability.