CVE-2024-31165
Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::SetFieldAction::unpack.
A network attacker may cause a Denial-of-Service (DoS) condition on the target component.
September 12, 2024
This issue affects libfluid v0.1.0
CVE-2024-31165
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3
Until a software patch which fixes this issue is not released, it is highly recommended not to expose the vulnerable component inside an untrusted network.
Gabriele Quagliarella of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more