CVE-2023-29933: Medium severity llvm llvm vulnerability
Published May 5, 2023
·Updated
llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.
Affected Software
7 affected componentsFixes available
ubuntu/llvm-toolchain-15<1:15.0.7-0ubuntu0.22.04.3
1:15.0.7-0ubuntu0.22.04.3
ubuntu/llvm-toolchain-15<1:15.0.7-3ubuntu0.23.04.1
1:15.0.7-3ubuntu0.23.04.1
debian/llvm-toolchain-13<=1:13.0.1-6~deb10u4, <=1:13.0.1-6~deb11u1, <=1:13.0.1-11
debian/llvm-toolchain-14<=1:14.0.6-12, <=1:14.0.6-16
debian/llvm-toolchain-15<=1:15.0.6-4
1:15.0.7-10
LLVM LLVM=2022-12-11
LLVM=2022-12-11
Remediation
Patch Available
Event History
May 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29933?
CVE-2023-29933 is classified as a high severity vulnerability due to its potential to cause a segmentation fault.
2
How do I fix CVE-2023-29933?
To fix CVE-2023-29933, you should upgrade to the recommended versions of llvm-toolchain-15 and apply any pertinent security patches.
3
What components are affected by CVE-2023-29933?
CVE-2023-29933 specifically affects the mlir::Block::getArgument component in the llvm-project.
4
What versions of llvm-toolchain are impacted by CVE-2023-29933?
CVE-2023-29933 affects llvm-toolchain-13, llvm-toolchain-14, and certain versions of llvm-toolchain-15.
5
Is CVE-2023-29933 present in Ubuntu or Debian releases?
Yes, CVE-2023-29933 is present in specific versions of llvm-toolchain packages in both Ubuntu and Debian distributions.