REDHAT-BUG-2211828: Low severity Gnome GLib vulnerability
Published Jun 2, 2023
·Updated
GLib's GVariant deserialization prior to GLib 2.74.4 failed to validate the input conforms to the expected format, leading to denial of service.
Referenves: https://gitlab.gnome.org/GNOME/glib/-/issues/2794
Affected Software
1 affected component
Gnome GLib<2.74.4
Event History
Jun 2, 2023
Data Sourced
via Red Hat·07:17 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2211828?
The severity of REDHAT-BUG-2211828 is classified as denial of service due to improper input validation in GLib's GVariant deserialization.
2
How do I fix REDHAT-BUG-2211828?
To fix REDHAT-BUG-2211828, update GLib to version 2.74.4 or later.
3
Which versions of GLib are affected by REDHAT-BUG-2211828?
GLib versions prior to 2.74.4 are affected by REDHAT-BUG-2211828.
4
What causes the vulnerability in REDHAT-BUG-2211828?
The vulnerability in REDHAT-BUG-2211828 is caused by GLib's GVariant deserialization failing to validate input format.
5
Is there a workaround for REDHAT-BUG-2211828?
Currently, there is no officially recommended workaround for REDHAT-BUG-2211828 other than updating to the fixed version.