CVE-2023-32611: G_variant_byteswap() can take a long time with some non-normal inputs
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
Other sources
Gvariantbyteswap() can take a long time with some non-normal inputs
— Microsoft
GLib's GVariant deserialization prior to GLib 2.74.4 is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
References: https://gitlab.gnome.org/GNOME/glib/-/issues/2797
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.64.6-1~ubuntu20.04.6 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.72.4-0ubuntu2.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.74.3-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.75.1Fixed in 2.74.4 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.56.4-0ubuntu0.18.04.9+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.40.2-0ubuntu1.1+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.48.2-0ubuntu4.8+ - Upgrade
Upgrade
debian/glib2.0to a version that resolves this vulnerability.Fixed in 2.58.3-2+deb10u5Fixed in 2.66.8-1+deb11u1Fixed in 2.74.6-2Fixed in 2.78.4-1Fixed in 2.78.4-3
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in GLib?
The vulnerability ID is CVE-2023-32611.
What is the severity level of CVE-2023-32611?
The severity level of CVE-2023-32611 is medium with a CVSS score of 5.5.
How does the GLib vulnerability CVE-2023-32611 affect the software?
The GLib vulnerability CVE-2023-32611 affects Gnome Glib versions up to and excluding 2.74.2.
What is the impact of CVE-2023-32611?
CVE-2023-32611 can cause excessive processing, leading to denial of service.
Is there a fix available for CVE-2023-32611?
Yes, updates and patches are available to fix CVE-2023-32611. It is recommended to update to a version above 2.74.2.