CVE-2023-29499: Gvariant offset table entry size is not checked in is_normal()
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Other sources
GLib's GVariant deserialization prior to GLib 2.74.4 failed to validate the input conforms to the expected format, leading to denial of service.
Referenves: https://gitlab.gnome.org/GNOME/glib/-/issues/2794
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.64.6-1~ubuntu20.04.6 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.72.4-0ubuntu2.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.74.3-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.75.1Fixed in 2.74.4 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.56.4-0ubuntu0.18.04.9+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.40.2-0ubuntu1.1+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.48.2-0ubuntu4.8+ - Upgrade
Upgrade
debian/glib2.0to a version that resolves this vulnerability.Fixed in 2.58.3-2+deb10u5Fixed in 2.66.8-1+deb11u1Fixed in 2.74.6-2Fixed in 2.78.4-1Fixed in 2.78.4-3
Event History
Frequently Asked Questions
What is CVE-2023-29499?
CVE-2023-29499 is a vulnerability in GLib where GVariant deserialization fails to validate input, leading to denial of service.
What is the severity of CVE-2023-29499?
The severity of CVE-2023-29499 is high with a CVSS score of 7.5.
How does CVE-2023-29499 impact GLib?
CVE-2023-29499 impacts GLib by causing GVariant deserialization to fail to validate input, potentially leading to denial of service.
How can I mitigate CVE-2023-29499 in GLib?
To mitigate CVE-2023-29499 in GLib, update to version 2.74.4 or later.
Where can I find more information about CVE-2023-29499?
You can find more information about CVE-2023-29499 in GLib at the following references: [link1], [link2], [link3].