Cnv: dos through repeatedly calling vm-dump-metrics until virt handler crashes
Vulnerability Description
A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-31420
Credits & Attribution
No credits recorded in the NVD database.
References
More from Unknown
View All →Affected Vendor
Unknown
View all reports →