CVE-2023-29934: Medium severity llvm llvm vulnerability
Published May 5, 2023
·Updated
llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().
Affected Software
11 affected componentsFixes available
ubuntu/llvm-toolchain-13<1:13.0.1-2ubuntu2.2
1:13.0.1-2ubuntu2.2
ubuntu/llvm-toolchain-13<1:13.0.1-11ubuntu14.1
1:13.0.1-11ubuntu14.1
ubuntu/llvm-toolchain-14<1:14.0.0-1ubuntu1.1
1:14.0.0-1ubuntu1.1
ubuntu/llvm-toolchain-14<1:14.0.6-12ubuntu0.23.04.1
1:14.0.6-12ubuntu0.23.04.1
ubuntu/llvm-toolchain-15<1:15.0.7-0ubuntu0.22.04.3
1:15.0.7-0ubuntu0.22.04.3
ubuntu/llvm-toolchain-15<1:15.0.7-3ubuntu0.23.04.1
1:15.0.7-3ubuntu0.23.04.1
debian/llvm-toolchain-13<=1:13.0.1-6~deb10u4, <=1:13.0.1-6~deb11u1, <=1:13.0.1-11
debian/llvm-toolchain-14<=1:14.0.6-12
1:14.0.6-16
debian/llvm-toolchain-15<=1:15.0.6-4
1:15.0.7-10
LLVM LLVM=2022-11-22
LLVM=2022-11-22
Remediation
Patch Available
Event History
May 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:19 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29934?
CVE-2023-29934 is classified as a segmentation fault vulnerability in llvm-project.
2
How do I fix CVE-2023-29934?
To fix CVE-2023-29934, update to the patched versions of llvm-toolchain-13, llvm-toolchain-14, or llvm-toolchain-15 as specified for your distribution.
3
What software is affected by CVE-2023-29934?
CVE-2023-29934 affects various versions of llvm-toolchain for Ubuntu and Debian.
4
Is CVE-2023-29934 exploitable?
CVE-2023-29934 can potentially be exploited to cause a segmentation fault, leading to application crashes.
5
What are the correct patched versions for CVE-2023-29934?
Patched versions for CVE-2023-29934 include llvm-toolchain-13 versions up to 1:13.0.1-11 and llvm-toolchain-14 versions up to 1:14.0.6-12, among others.