CVE-2023-29932: Buffer Overflow
Published May 5, 2023
·Updated
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.
Affected Software
12 affected componentsFixes available
ubuntu/llvm-toolchain-15<1:15.0.7-0ubuntu0.22.04.3
1:15.0.7-0ubuntu0.22.04.3
ubuntu/llvm-toolchain-15<1:15.0.7-3ubuntu0.23.04.1
1:15.0.7-3ubuntu0.23.04.1
ubuntu/llvm-toolchain-14<1:14.0.6-12ubuntu0.23.04.1
1:14.0.6-12ubuntu0.23.04.1
ubuntu/llvm-toolchain-14<1:14.0.0-1ubuntu1.1
1:14.0.0-1ubuntu1.1
ubuntu/llvm-toolchain-13<1:13.0.1-2ubuntu2.2
1:13.0.1-2ubuntu2.2
ubuntu/llvm-toolchain-13<1:13.0.1-11ubuntu14.1
1:13.0.1-11ubuntu14.1
debian/llvm-toolchain-13<=1:13.0.1-6~deb10u4, <=1:13.0.1-6~deb11u1, <=1:13.0.1-11
debian/llvm-toolchain-14<=1:14.0.6-12
1:14.0.6-16
debian/llvm-toolchain-15<=1:15.0.6-4
1:15.0.7-10
llvm llvm=2022-11-01
Microsoft cbl2 llvm 12.0.1-8
Microsoft cbl2 rust 1.72.0-2
Remediation
Patch Available
Event History
May 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
May 9, 2023
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jan 12, 2024
Data Sourced
via Launchpad·12:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29932?
CVE-2023-29932 is classified with a medium severity level due to its potential to cause segmentation faults.
2
How do I fix CVE-2023-29932?
To fix CVE-2023-29932, upgrade to the patched versions of llvm-toolchain-15, llvm-toolchain-14, or llvm-toolchain-13 as specified in the remediation list.
3
Which versions of llvm-toolchain are affected by CVE-2023-29932?
CVE-2023-29932 affects specific versions of llvm-toolchain including 13.x, 14.x, and 15.x prior to their patched releases.
4
Is CVE-2023-29932 exploitable in production environments?
Yes, CVE-2023-29932 is exploitable in production environments that utilize the affected versions of the llvm-toolchain.
5
What is the nature of the issue in CVE-2023-29932?
CVE-2023-29932 involves a segmentation fault caused by a flaw in the mlir::IROperand component of the llvm-project.