CVE-2023-29499

Updated: 2023-11-27 19:08:50.061485

Description:

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU glib2 2.68.4 7.5 HIGH Already Fixed 2023-11-10 02:29:57
CentOS 6 ELS glib2 2.28.8 7.5 HIGH Ignored 2023-10-26 07:39:34
CentOS 7 ELS glib2 2.56.1 7.5 HIGH Released CLSA-2023:1697135256 2023-10-12 17:08:12
CentOS 8.4 ELS glib2 2.56.4-10 7.5 HIGH Released CLSA-2023:1697740212 2023-10-19 21:08:44
CentOS 8.5 ELS glib2 2.56.4-156 7.5 HIGH Released CLSA-2023:1697740947 2023-10-19 21:08:42
CloudLinux 6 ELS glib2 2.28.8 7.5 HIGH Ignored 2023-10-26 07:39:34
Oracle Linux 6 ELS glib2 2.28.8 7.5 HIGH Ignored 2023-10-26 07:39:34
Ubuntu 16.04 ELS glib2.0 2.48.2-0 7.5 HIGH Released CLSA-2023:1697741722 2023-10-19 21:08:49
Ubuntu 18.04 ELS glib2.0 2.56.4-0 7.5 HIGH Released CLSA-2023:1697741849 2023-10-19 21:08:50

Statement

We've reasoned not to port the fix since the version of the library is very old and requires tremendous efforts to backport a large amount of sources from the upstream and there is very high risk of breaking the functionality of the library in the process.