CVE-2023-29939: Medium severity llvm llvm vulnerability
Published May 5, 2023
·Updated
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).
Affected Software
11 affected componentsFixes available
debian/llvm-toolchain-13<=1:13.0.1-6~deb10u4, <=1:13.0.1-6~deb11u1, <=1:13.0.1-11
debian/llvm-toolchain-14<=1:14.0.6-12
1:14.0.6-16
debian/llvm-toolchain-15<=1:15.0.6-4
1:15.0.7-10
ubuntu/llvm-toolchain-13<1:13.0.1-2ubuntu2.2
1:13.0.1-2ubuntu2.2
ubuntu/llvm-toolchain-13<1:13.0.1-11ubuntu14.1
1:13.0.1-11ubuntu14.1
ubuntu/llvm-toolchain-14<1:14.0.0-1ubuntu1.1
1:14.0.0-1ubuntu1.1
ubuntu/llvm-toolchain-14<1:14.0.6-12ubuntu0.23.04.1
1:14.0.6-12ubuntu0.23.04.1
ubuntu/llvm-toolchain-15<1:15.0.7-0ubuntu0.22.04.3
1:15.0.7-0ubuntu0.22.04.3
ubuntu/llvm-toolchain-15<1:15.0.7-3ubuntu0.23.04.1
1:15.0.7-3ubuntu0.23.04.1
LLVM LLVM=2023-01-12
LLVM=2023-01-12
Remediation
Patch Available
Event History
May 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29939?
CVE-2023-29939 has been classified as a vulnerability that leads to a segmentation fault in the llvm-project.
2
How do I fix CVE-2023-29939?
To fix CVE-2023-29939, you should upgrade to the patched versions of llvm-toolchain-14 or llvm-toolchain-15 as specified in the remediation details.
3
Which versions are affected by CVE-2023-29939?
CVE-2023-29939 affects specific versions of llvm-toolchain-13, llvm-toolchain-14, and llvm-toolchain-15 prior to the patched releases.
4
What components does CVE-2023-29939 impact?
CVE-2023-29939 impacts the mlir::spirv::TargetEnv component in the llvm-project.
5
What operating systems are affected by CVE-2023-29939?
CVE-2023-29939 affects Debian and Ubuntu distributions using the vulnerable llvm-toolchain packages.