Resource exhaustion in llvm-project - CVE-2024-31852
Published: June 6, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to LLVM generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Observability with Instana
Anolis OS
llvm
llvm-devel
llvm-googletest
llvm-libs
llvm-static
llvm-test
llvm-doc
How to mitigate CVE-2024-31852
IBM Observability with Instana - update to 1.0.297
llvm - update to 17.0.6-7
llvm-devel - update to 17.0.6-7
llvm-googletest - update to 17.0.6-7
llvm-libs - update to 17.0.6-7
llvm-static - update to 17.0.6-7
llvm-test - update to 17.0.6-7
llvm-doc - update to 17.0.6-7