CVE-2016-6323: High severity gnu c library (glibc) vulnerability
Last updated 24 July 2024
Other sources
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6323?
CVE-2016-6323 has a medium severity rating, primarily impacting ARM EABI (32-bit) platforms.
How do I fix CVE-2016-6323?
You can fix CVE-2016-6323 by upgrading to glibc version 2.25 or later.
Which versions of glibc are affected by CVE-2016-6323?
CVE-2016-6323 affects glibc versions prior to 2.25, specifically up to 2.24.
What kind of attacks are possible with CVE-2016-6323?
CVE-2016-6323 may allow context-dependent attackers to cause a denial of service, leading to system hangs.
On which platforms does CVE-2016-6323 have an impact?
CVE-2016-6323 specifically affects ARM EABI (32-bit) platforms using the affected versions of glibc.