USN-6258-1: LLVM Toolchain vulnerabilities
It was discovered that LLVM Toolchain did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted MLIR file, an attacker could possibly use this issue to cause LLVM Toolchain to crash, resulting in a denial of service. (CVE-2023-29932, CVE-2023-29934, CVE-2023-29939) It was discovered that LLVM Toolchain did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted MLIR file, an attacker could possibly use this issue to cause LLVM Toolchain to crash, resulting in a denial of service. This issue only affected llvm-toolchain-15. (CVE-2023-29933)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6258-1?
USN-6258-1 is categorized as a denial of service vulnerability due to improper memory management in the LLVM Toolchain.
How do I fix USN-6258-1?
To fix USN-6258-1, update the affected packages to the recommended versions provided in the Ubuntu advisory.
What products are affected by USN-6258-1?
USN-6258-1 affects specific versions of LLVM and MLIR tools on Ubuntu 22.04 and 23.04.
Can USN-6258-1 be exploited by opening files?
Yes, USN-6258-1 could be exploited if a user opens a specially crafted MLIR file.
Is it necessary to take action on USN-6258-1?
Yes, it is recommended to address USN-6258-1 to prevent potential denial of service attacks.