CVE-2023-32636: Input Validation
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
Other sources
GLib's GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499
References: https://gitlab.gnome.org/GNOME/glib/-/issues/2841
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.56.4-0ubuntu0.18.04.9+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.40.2-0ubuntu1.1+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.48.2-0ubuntu4.8+ - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.64.6-1~ubuntu20.04.6 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.72.4-0ubuntu2.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.74.3-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.75.1Fixed in 2.74.4 - Upgrade
Upgrade
debian/glib2.0to a version that resolves this vulnerability.Fixed in 2.58.3-2+deb10u3Fixed in 2.58.3-2+deb10u5Fixed in 2.66.8-1+deb11u1Fixed in 2.74.6-2Fixed in 2.78.4-1Fixed in 2.78.4-3
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in glib?
The vulnerability ID for this flaw in glib is CVE-2023-32636.
What is the severity of CVE-2023-32636?
The severity of CVE-2023-32636 is high (7.5).
How does the gvariant deserialization code in glib become vulnerable?
The gvariant deserialization code in glib becomes vulnerable due to a flaw introduced by additional input validation added to resolve CVE-2023-29499.
Which version of glib is affected by this vulnerability?
The vulnerability affects glib versions up to (but not including) 2.74.4.
Is there a fix available for this vulnerability in glib?
Yes, multiple fixes have been released for the gvariant deserialization code in glib to address this vulnerability.