Libndp: buffer overflow in route information length field
Vulnerability Description
A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5564
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Upstream acknowledges Evgeny Vereshchagin as the original reporter.
References
- https://access.redhat.com/errata/RHBA-2025:6631
- https://access.redhat.com/errata/RHSA-2024:4618
- https://access.redhat.com/errata/RHSA-2024:4619
- https://access.redhat.com/errata/RHSA-2024:4620
- https://access.redhat.com/errata/RHSA-2024:4622
- https://access.redhat.com/errata/RHSA-2024:4636
- https://access.redhat.com/errata/RHSA-2024:4640
- https://access.redhat.com/errata/RHSA-2024:4641
- https://access.redhat.com/errata/RHSA-2024:4642
- https://access.redhat.com/errata/RHSA-2024:4643
- https://access.redhat.com/security/cve/CVE-2024-5564
- https://bugzilla.redhat.com/show_bug.cgi?id=2284122
More from Unknown
View All →Affected Vendor
Unknown
View all reports →