CVE-2023-26257: High severity genivi alliance dlt-daemon vulnerability
Published Feb 27, 2023
·Updated
An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.
Affected Software
1 affected component
COVESA dlt-daemon<=2.18.8
Remediation
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-26257.
2
What is the severity of CVE-2023-26257?
CVE-2023-26257 has a severity of high.
3
What is the affected software?
The affected software is Covesa Dlt-daemon version up to and including 2.18.8.
4
How can I fix CVE-2023-26257?
To fix CVE-2023-26257, update to a version of Covesa Dlt-daemon that is higher than 2.18.8.
5
Are there any references related to CVE-2023-26257?
Yes, you can find references for CVE-2023-26257 at the following links: [GitHub Issue](https://github.com/COVESA/dlt-daemon/issues/440) and [GitHub Commit](https://github.com/COVESA/dlt-daemon/pull/441/commits/b6149e203f919c899fefc702a17fbb78bdec3700).