CVE Vulnerabilities

CVE-2024-27099

Double Free

Published: Feb 27, 2024 | Modified: Feb 14, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
Ubuntu
MEDIUM

The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect AMQP_VALUE failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.

Weakness

The product calls free() twice on the same memory address.

Affected Software

Name Vendor Start Version End Version
Azure_uamqp Microsoft * 2023-2-08 (excluding)
Azure-uamqp-python Ubuntu focal *
Azure-uamqp-python Ubuntu mantic *
Azure-uamqp-python Ubuntu oracular *

Potential Mitigations

References