Vulnerability record · CVE-2024-0217 · published 3 January 2024
CVE-2024-0217: Packagekit project packagekit use after free vulnerability
Packagekit Project · Packagekit
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
Description
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2024-0217 | MitigationThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2256624 | Issue TrackingPatchThird Party Advisory |
| https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 | Patch |
| https://access.redhat.com/security/cve/CVE-2024-0217 | MitigationThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2256624 | Issue TrackingPatchThird Party Advisory |
| https://github.com/PackageKit/PackageKit/commit/64278c9127e3333342b56ead99556161f7e86f79 | Patch |
Track CVE-2024-0217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0217), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.