[Debian] High CVE: CVE-2023-4911 glibc

Bug #2038708 reported by Yue Tao
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
High
Li Zhou

Bug Description

CVE-2023-4911: https://nvd.nist.gov/vuln/detail/CVE-2023-4911

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Base Score: High

Reference:

['libc6_2.31-13+deb11u6_amd64.deb===>libc6_2.31-13+deb11u7_amd64.deb', 'libc6-dev_2.31-13+deb11u6_amd64.deb===>libc6-dev_2.31-13+deb11u7_amd64.deb', 'libc-bin_2.31-13+deb11u6_amd64.deb===>libc-bin_2.31-13+deb11u7_amd64.deb', 'libc-dev-bin_2.31-13+deb11u6_amd64.deb===>libc-dev-bin_2.31-13+deb11u7_amd64.deb', 'libc-l10n_2.31-13+deb11u6_all.deb===>libc-l10n_2.31-13+deb11u7_all.deb', 'locales_2.31-13+deb11u6_all.deb===>locales_2.31-13+deb11u7_all.deb', 'locales-all_2.31-13+deb11u6_amd64.deb===>locales-all_2.31-13+deb11u7_amd64.deb']
https://www.debian.org/security/2023/dsa-5514
https://www.tenable.com/plugins/nessus/182473

CVE References

Li Zhou (lzhou2)
Changed in starlingx:
assignee: nobody → Li Zhou (lzhou2)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tools (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/tools/+/898081

Changed in starlingx:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tools (master)

Reviewed: https://review.opendev.org/c/starlingx/tools/+/898081
Committed: https://opendev.org/starlingx/tools/commit/a84aae22a927e5c89833076eadf98226d84cc8f1
Submitter: "Zuul (22348)"
Branch: master

commit a84aae22a927e5c89833076eadf98226d84cc8f1
Author: Li Zhou <email address hidden>
Date: Fri Oct 6 23:37:33 2023 -0700

    Debian: glibc: fix CVE-2023-4911

    Upgrade glibc related packages' version from 2.31-13+deb11u6
    to 2.31-13+deb11u7 to fix CVE-2023-4911.

    Test Plan:
     Pass: downloader
     Pass: build-pkgs --clean --all
     Pass: build-image
     Pass: boot

    Closes-bug: #2038708

    Signed-off-by: Li Zhou <email address hidden>
    Change-Id: Ic3da36041676ff43de5d6170c5d76a3995a9113f

Changed in starlingx:
status: In Progress → Fix Released
Yue Tao (wrytao)
description: updated
Yue Tao (wrytao)
description: updated
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.