CVE-2024-5564: Libndp: buffer overflow in route information length field
A vulnerability was found in libndp. A buffer overflow in NetworkManager that can be triggered by sending a malformed IPv6 router advertisement packet via malicious user locally. This happens as libndp was not validating correctly the route length information and hence leading to a flaw. This affects versions of libndp >= 1.0.
Other sources
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
— Launchpad
libndp is vulnerable to a buffer overflow, caused by improper bounds checking by NetworkManager. By sending a specially crafted IPv6 router advertisement packet, an attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
Libndp: buffer overflow in route information length field
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libndpto a version that resolves this vulnerability.Fixed in 1.6-1+deb11u1Fixed in 1.8-1+deb12u1Fixed in 1.9-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5564?
CVE-2024-5564 has been classified as a high severity vulnerability due to the potential for a buffer overflow that can be exploited locally.
How do I fix CVE-2024-5564?
To fix CVE-2024-5564, update to the latest version of libndp that addresses the buffer overflow vulnerability.
What software is affected by CVE-2024-5564?
CVE-2024-5564 affects libndp version 1.0 and later versions before the patch is applied.
What type of attack can exploit CVE-2024-5564?
CVE-2024-5564 can be exploited through locally sending a malformed IPv6 router advertisement packet.
Is there a known exploit for CVE-2024-5564?
While there are no public exploits reported for CVE-2024-5564, the vulnerability is critical to address due to the potential impacts.