First published: Fri Jun 02 2023(Updated: )
GLib's GVariant deserialization prior to GLib 2.74.4 is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service. References: <a href="https://gitlab.gnome.org/GNOME/glib/-/issues/2797">https://gitlab.gnome.org/GNOME/glib/-/issues/2797</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GLib | <2.74.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2211829 is classified as a denial of service vulnerability, which can lead to resource exhaustion.
To fix REDHAT-BUG-2211829, upgrade GLib to version 2.74.4 or later.
The issue in REDHAT-BUG-2211829 is caused by a crafted GVariant that leads to excessive processing during deserialization.
GLib versions prior to 2.74.4 are affected by REDHAT-BUG-2211829.
Yes, REDHAT-BUG-2211829 can be exploited remotely if an application uses vulnerable GLib for processing GVariants.