Buffer overflow in Liblouis - CVE-2023-26768
Published: April 6, 2023
Vulnerability identifier: #VU74500
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26768
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
Affected software
Liblouis
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
Desktop Applications Module
openSUSE Leap
Ubuntu
liblouis-bin (Ubuntu package)
liblouis9 (Ubuntu package)
python-louis (Ubuntu package)
liblouis20 (Ubuntu package)
python3-louis
liblouis-doc
liblouis
liblouis (Red Hat package)
liblouis-tools
liblouis-debuginfo
liblouis-tools-debuginfo
liblouis20-debuginfo
liblouis-devel
liblouis20
liblouis-debugsource
liblouis-data
dev-libs/liblouis
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
Desktop Applications Module
openSUSE Leap
Ubuntu
liblouis-bin (Ubuntu package)
liblouis9 (Ubuntu package)
python-louis (Ubuntu package)
liblouis20 (Ubuntu package)
python3-louis
liblouis-doc
liblouis
liblouis (Red Hat package)
liblouis-tools
liblouis-debuginfo
liblouis-tools-debuginfo
liblouis20-debuginfo
liblouis-devel
liblouis20
liblouis-debugsource
liblouis-data
dev-libs/liblouis
How to mitigate CVE-2023-26768
Install updates from vendor's website.
Liblouis - update to 3.25.0
liblouis-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.0-1ubuntu0.5, 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
liblouis9 (Ubuntu package) - update to Ubuntu Pro
python-louis (Ubuntu package) - update to 3.5.0-1ubuntu0.5
liblouis20 (Ubuntu package) - addressed in versions 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
python3-louis - update to 3.16.1-5
liblouis-doc - update to 3.16.1-5
liblouis - update to 3.16.1-5
liblouis (Red Hat package) - update to 3.16.1-5.el9
liblouis-doc - update to 3.20.0-150400.3.13.1
python3-louis - update to 3.20.0-150400.3.13.1
liblouis-tools - update to 3.20.0-150400.3.13.1
liblouis-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-tools-debuginfo - update to 3.20.0-150400.3.13.1
liblouis20-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-devel - update to 3.20.0-150400.3.13.1
liblouis20 - update to 3.20.0-150400.3.13.1
liblouis-debugsource - update to 3.20.0-150400.3.13.1
liblouis-data - update to 3.20.0-150400.3.13.1
dev-libs/liblouis - update to 3.25.0
liblouis-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.0-1ubuntu0.5, 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
liblouis9 (Ubuntu package) - update to Ubuntu Pro
python-louis (Ubuntu package) - update to 3.5.0-1ubuntu0.5
liblouis20 (Ubuntu package) - addressed in versions 3.12.0-3ubuntu0.2, 3.20.0-2ubuntu0.2, 3.22.0-2ubuntu0.1, 3.24.0-1ubuntu0.1
python3-louis - update to 3.16.1-5
liblouis-doc - update to 3.16.1-5
liblouis - update to 3.16.1-5
liblouis (Red Hat package) - update to 3.16.1-5.el9
liblouis-doc - update to 3.20.0-150400.3.13.1
python3-louis - update to 3.20.0-150400.3.13.1
liblouis-tools - update to 3.20.0-150400.3.13.1
liblouis-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-tools-debuginfo - update to 3.20.0-150400.3.13.1
liblouis20-debuginfo - update to 3.20.0-150400.3.13.1
liblouis-devel - update to 3.20.0-150400.3.13.1
liblouis20 - update to 3.20.0-150400.3.13.1
liblouis-debugsource - update to 3.20.0-150400.3.13.1
liblouis-data - update to 3.20.0-150400.3.13.1
dev-libs/liblouis - update to 3.25.0
External References
Related Security Bulletins
- Buffer overflow in liblouis
- Ubuntu update for liblouis
- SUSE update for liblouis
- Ubuntu update for liblouis
- Multiple vulnerabilities in Oracle Solaris third-party software
- Red Hat Enterprise Linux 9 update for liblouis
- Multiple vulnerabilities in Oracle Linux
- Gentoo update for liblouis
- Anolis OS update for liblouis