[Debian] High CVE: CVE-2023-38403 iperf3: integer overflow and heap corruption

Bug #2029210 reported by Yue Tao
260
This bug affects 2 people
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
High
Wentao Zhang

Bug Description

CVE-2023-38403: https://nvd.nist.gov/vuln/detail/CVE-2023-38403

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

Base Score: High

References:

['iperf3_3.9-1_amd64.deb===>iperf3_3.9-1+deb11u1_amd64.deb', 'libiperf0_3.9-1_amd64.deb===>libiperf0_3.9-1+deb11u1_amd64.deb']

CVE References

Yue Tao (wrytao)
tags: added: stx.9.0 stx.security
removed: stx.9
Wentao Zhang (wzhang4)
Changed in starlingx:
assignee: nobody → Wentao Zhang (wzhang4)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tools (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/tools/+/891931

Changed in starlingx:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tools (master)

Reviewed: https://review.opendev.org/c/starlingx/tools/+/891931
Committed: https://opendev.org/starlingx/tools/commit/67004af13a4f3ec834f6d3a81647896d142b21a3
Submitter: "Zuul (22348)"
Branch: master

commit 67004af13a4f3ec834f6d3a81647896d142b21a3
Author: Wentao Zhang <email address hidden>
Date: Sun Aug 20 20:03:22 2023 -0700

    Debian: package : fix CVE-2023-38403

    Upgrade iperf3 to 3.9-1+deb11u1
    Upgrade libiperf0 to 3.9-1+deb11u1

    Refer to:
    https://nvd.nist.gov/vuln/detail/CVE-2023-38403

    Test Plan:
    Pass: downloader
    Pass: build-pkgs --clean --all
    Pass: build-image
    Pass: boot

    Closes-bug: #2029210

    Signed-off-by: Wentao Zhang <email address hidden>
    Change-Id: I2147dec036cb22b33633d8bd459439e97efcdf88

Changed in starlingx:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.