First published: Fri Jun 02 2023(Updated: )
GLib's GVariant deserialization prior to GLib 2.74.4 failed to validate the input conforms to the expected format, leading to denial of service. Referenves: <a href="https://gitlab.gnome.org/GNOME/glib/-/issues/2794">https://gitlab.gnome.org/GNOME/glib/-/issues/2794</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME libraries | <2.74.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2211828 is classified as denial of service due to improper input validation in GLib's GVariant deserialization.
To fix REDHAT-BUG-2211828, update GLib to version 2.74.4 or later.
GLib versions prior to 2.74.4 are affected by REDHAT-BUG-2211828.
The vulnerability in REDHAT-BUG-2211828 is caused by GLib's GVariant deserialization failing to validate input format.
Currently, there is no officially recommended workaround for REDHAT-BUG-2211828 other than updating to the fixed version.