Description
A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1311 | A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine. |
Github GHSA |
GHSA-vjhf-6xfr-5p9g | KubeVirt NULL pointer dereference flaw |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T19:12:24.292Z
Reserved: 2024-04-03T12:10:43.208Z
Link: CVE-2024-31420
Updated: 2024-08-02T01:52:56.848Z
Status : Deferred
Published: 2024-04-03T14:15:18.310
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-31420
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA