A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetapp Active Iq Unified Manager
APPNetappall versionsNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsSystemd Project Systemd
APPSystemd Project240
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
Related vulnerabilities
CVE-2024-54085CRITICAL10.0⚠ KEVPL ✓same product
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2024-40896CRITICAL9.1PL ✓same product
XXE w bibliotece libxml2 — obejście niestandardowych handlerów SAX
CVE-2024-52533CRITICAL9.8PL ✓same product
Buffer overflow w GNOME GLib — błąd off-by-one w obsłudze SOCKS4
CVE-2024-47561CRITICAL9.2PL ✓same product
Apache Avro Java SDK — RCE przez niebezpieczną deserializację schematu