REDHAT-BUG-2211827: Low severity Gnome GLib vulnerability
Published Jun 2, 2023
·Updated
GLib's GVariant deserialization prior to GLib 2.74.4 is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.
References: https://gitlab.gnome.org/GNOME/glib/-/issues/2121
Affected Software
1 affected component
Gnome GLib<2.74.4
Event History
Jun 2, 2023
Data Sourced
via Red Hat·07:13 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2211827?
REDHAT-BUG-2211827 has a high severity due to its potential to cause denial of service through excessive processing.
2
How do I fix REDHAT-BUG-2211827?
To fix REDHAT-BUG-2211827, upgrade GLib to version 2.74.4 or later.
3
What is the impact of REDHAT-BUG-2211827?
The impact of REDHAT-BUG-2211827 includes the risk of denial of service, making applications unresponsive.
4
Which versions of GLib are affected by REDHAT-BUG-2211827?
GLib versions prior to 2.74.4 are affected by REDHAT-BUG-2211827.
5
Is there a workaround for REDHAT-BUG-2211827?
Currently, there are no known workarounds for REDHAT-BUG-2211827 other than upgrading the software.