Resource exhaustion in Gnome GLib - CVE-2023-32611

 

Resource exhaustion in Gnome GLib - CVE-2023-32611

Published: June 15, 2023


Vulnerability identifier: #VU77350
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32611
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the g_variant_byteswap() function. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Gnome GLib
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE CaaS Platform
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Oracle Solaris
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Red Hat OpenShift Builds
cert-manager Operator for Red Hat OpenShift
OpenShift Logging
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Splunk Operator for Kubernetes Add-on
Red Hat Migration Toolkit for Applications
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
VMware Tanzu Operations Manager
RecoverPoint for Virtual Machines
SmartFabric OS10
webMethods Managed File Transfer
Platform Automation Toolkit
libglib2.0-bin (Ubuntu package)
libglib2.0-0 (Ubuntu package)
libgthread-2_0-0-debuginfo
libgobject-2_0-0-32bit-debuginfo
glib2-debugsource
libglib-2_0-0-debuginfo
libgio-2_0-0-debuginfo
glib2-tools-debuginfo
glib2-lang
libglib-2_0-0-32bit
libgmodule-2_0-0-32bit-debuginfo
libgobject-2_0-0-32bit
libgio-2_0-0-32bit-debuginfo
libgmodule-2_0-0-32bit
libgio-2_0-0-32bit
libglib-2_0-0-32bit-debuginfo
libgobject-2_0-0-debuginfo
libgobject-2_0-0
libgmodule-2_0-0-debuginfo
glib2-devel
glib2-tools
glib2-devel-debuginfo
libgmodule-2_0-0
libgio-2_0-0
libglib-2_0-0
libgthread-2_0-0
glib2-doc
glib2-tests
glib2
glib2-static
glib2 (Red Hat package)
dev-libs/glib
mingw-glib2
mingw-glib2 (Red Hat package)
Network Observability plugin for the Openshift Console
Red Hat Ceph Storage
IBM CICS TX Advanced

How to mitigate CVE-2023-32611

Install updates from vendor's website.

Gnome GLib - addressed in versions 2.74.4, 2.75.1
Isolation Segment - addressed in versions 3.0.20, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 3.0.20, 4.0.12
Red Hat OpenShift Builds - update to 1.0.1
SmartFabric Storage Software - update to 1.4.3
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
OpenShift Virtualization - addressed in versions 4.13.6, 4.14.1
OpenShift Logging - update to 5.8.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
SmartFabric OS10 - update to 10.5.4.11
libglib2.0-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.6, 2.72.4-0ubuntu2.2, 2.74.3-0ubuntu1.2
libglib2.0-0 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.6, 2.72.4-0ubuntu2.2, 2.74.3-0ubuntu1.2
Network Observability plugin for the Openshift Console - update to 1.5.0
VMware Tanzu Operations Manager - addressed in versions 2.10.65, 3.0.12
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
libgthread-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
glib2-debugsource - update to 2.54.3-150000.4.29.1
libglib-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libgio-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
glib2-tools-debuginfo - update to 2.54.3-150000.4.29.1
glib2-lang - update to 2.54.3-150000.4.29.1
libglib-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libgio-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libgio-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libglib-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0 - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
glib2-devel - update to 2.54.3-150000.4.29.1
glib2-tools - update to 2.54.3-150000.4.29.1
glib2-devel-debuginfo - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0 - update to 2.54.3-150000.4.29.1
libgio-2_0-0 - update to 2.54.3-150000.4.29.1
libglib-2_0-0 - update to 2.54.3-150000.4.29.1
libgthread-2_0-0 - update to 2.54.3-150000.4.29.1
glib2-doc - update to 2.68.4-11
glib2-devel - update to 2.68.4-11
glib2-tests - update to 2.68.4-11
glib2 - update to 2.68.4-11
glib2-static - update to 2.68.4-11
glib2 (Red Hat package) - update to 2.68.4-11.el9
dev-libs/glib - update to 2.74.4
mingw-glib2 - addressed in versions 2.74.7-1.fc37, 2.74.7-1.fc38
glib2 - update to 2.74.7-688
mingw-glib2 (Red Hat package) - update to 2.78.0-1.el9
Splunk Operator for Kubernetes Add-on - update to 3.0.0
Platform Automation Toolkit - addressed in versions 4.4.19, 4.4.32, 5.0.0, 5.0.25, 5.1.0, 5.1.2
Red Hat Ceph Storage - update to 6.1
Red Hat Migration Toolkit for Applications - update to 6.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix21

External References

Related Security Bulletins