CVE-2024-6501

Public on 2024-07-07
Modified on 2024-09-13
Description
Given a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, someone could inject a malformed LLDP packet and NetworkManager would crash leading to a DoS.
Severity
Low severity
Low
CVSS v3 Base Score
3.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core NetworkManager Not Affected
Amazon Linux 2 - Core NetworkManager-libreswan Not Affected
Amazon Linux 2 - Core network-manager-applet Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
NVD CVSSv3 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L