First published: Mon Sep 25 2023(Updated: )
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <2.39 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
GNU glibc | >=2.34<2.39 | |
redhat/glibc | <2.39 | 2.39 |
ubuntu/glibc | <2.35-0ubuntu3.5 | 2.35-0ubuntu3.5 |
ubuntu/glibc | <2.37-0ubuntu2.2 | 2.37-0ubuntu2.2 |
ubuntu/glibc | <2.38-1ubuntu5 | 2.38-1ubuntu5 |
ubuntu/glibc | <2.38-1ubuntu5 | 2.38-1ubuntu5 |
debian/glibc | 2.31-13+deb11u10 2.36-9+deb12u7 2.39-6 | |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=ec6b95c3303c700eb89eebeda2d7264cc184a796
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5156 is a vulnerability in the GNU C Library that can cause a memory leak and application crashes.
CVE-2023-5156 has a severity rating of high (7.5).
The GNU C Library version up to 2.39, GNU glibc version up to 2.39, Redhat Enterprise Linux 8.0, and Redhat Enterprise Linux 9.0 are affected by CVE-2023-5156.
CVE-2023-5156 can be exploited by an attacker to cause a memory leak, potentially leading to application crashes.
Yes, a fix is available for CVE-2023-5156. Update to GNU C Library version 2.39 or newer.