CVE-2023-2602: Low severity Libcap Project Libcap vulnerability
A vulnerability was found in the pthreadcreate() function in libcap. This issue may allow a malicious actor to use cause realpthreadcreate() to return an error, which can exhaust the process memory.
Other sources
Original Report:
Source: libcap2 Version: 1:2.66-3 Severity: important Tags: security upstream X-Debbugs-Cc: carnil, Debian Security Team <team.org>
The following vulnerabilities were published for libcap2.
CVE-2023-2602[0]: | LCAP-CR-23-01 (Correct the check of pthreadcreate()'s return value)
[0] https://security-tracker.debian.org/tracker/CVE-2023-2602 https://www.cve.org/CVERecord?id=CVE-2023-2602
fixed in 1:2.66-4
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libcap2to a version that resolves this vulnerability.Fixed in 1:2.66-4+deb12u3Fixed in 1:2.75-10+deb13u1Fixed in 1:2.78-1 - Upgrade
Upgrade
libcap2to a version that resolves this vulnerability.Fixed in 1:2.66-4Patch LCAP-CR-23-01 (Correct the check of pthread_create()'s return value)
Event History
Frequently Asked Questions
What is CVE-2023-2602?
CVE-2023-2602 is a vulnerability found in the pthread_create() function in libcap that can allow a malicious actor to exhaust the process memory.
How severe is CVE-2023-2602?
CVE-2023-2602 has a severity level of low with a severity value of 3.3.
Which software is affected by CVE-2023-2602?
The affected software includes libcap2 (version 1:2.44-1), Libcap Project Libcap (version 2.66), Redhat Enterprise Linux (versions 6.0, 7.0, 8.0, 9.0), Debian Debian Linux (versions 10.0, 11.0, 12.0), and Fedoraproject Fedora (versions 37, 38).
How do I fix CVE-2023-2602?
To fix CVE-2023-2602, update the libcap2 package to versions 1:2.25-2 or 1:2.66-4.
Where can I find more information about CVE-2023-2602?
You can find more information about CVE-2023-2602 on the following pages: Red Hat Security Tracker, Debian Security Tracker, and CVE website.