REDHAT-BUG-2211829: Low severity Gnome GLib vulnerability
Published Jun 2, 2023
·Updated
GLib's GVariant deserialization prior to GLib 2.74.4 is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
References: https://gitlab.gnome.org/GNOME/glib/-/issues/2797
Affected Software
1 affected component
Gnome GLib<2.74.4
Event History
Jun 2, 2023
Data Sourced
via Red Hat·07:20 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2211829?
The severity of REDHAT-BUG-2211829 is classified as a denial of service vulnerability, which can lead to resource exhaustion.
2
How do I fix REDHAT-BUG-2211829?
To fix REDHAT-BUG-2211829, upgrade GLib to version 2.74.4 or later.
3
What causes the issue in REDHAT-BUG-2211829?
The issue in REDHAT-BUG-2211829 is caused by a crafted GVariant that leads to excessive processing during deserialization.
4
Which versions of GLib are affected by REDHAT-BUG-2211829?
GLib versions prior to 2.74.4 are affected by REDHAT-BUG-2211829.
5
Can REDHAT-BUG-2211829 be exploited remotely?
Yes, REDHAT-BUG-2211829 can be exploited remotely if an application uses vulnerable GLib for processing GVariants.