CVE-2023-32636

Updated: 2023-11-10 19:46:46.839898

Description:

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU glib2 2.68.4 7.5 HIGH Already Fixed 2023-11-21 13:10:34
CentOS 6 ELS glib2 2.28.8 7.5 HIGH Not Vulnerable 2023-10-25 17:07:09
CentOS 7 ELS glib2 2.56.1 7.5 HIGH Released CLSA-2023:1697135256 2023-10-12 17:08:08
CentOS 8.4 ELS glib2 2.56.4-10 7.5 HIGH Released CLSA-2023:1697740212 2023-10-19 21:08:37
CentOS 8.5 ELS glib2 2.56.4-156 7.5 HIGH Released CLSA-2023:1697740947 2023-10-19 21:08:36
CloudLinux 6 ELS glib2 2.28.8 7.5 HIGH Not Vulnerable 2023-10-25 17:07:09
Oracle Linux 6 ELS glib2 2.28.8 7.5 HIGH Not Vulnerable 2023-10-25 17:07:10
Ubuntu 16.04 ELS glib2.0 2.48.2-0 7.5 HIGH Released CLSA-2023:1697741722 2023-10-19 21:08:47
Ubuntu 18.04 ELS glib2.0 2.56.4-0 7.5 HIGH Released CLSA-2023:1697741849 2023-10-19 21:08:48