Buffer overflow in macOS - CVE-2023-38590
Published: July 31, 2023
Vulnerability identifier: #VU78764
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38590
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the OS kernel. A remote attacker can send specially crafted data to the system, trigger memory corruption and crash the kernel.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-38590
Install updates from vendor's website.
macOS - addressed in versions 13.5 22G74, 11.7.9 20G1426, 12.6.8 21G725
watchOS - update to 9.6 20U73
iPadOS - addressed in versions 15.7.8 19H364, 16.6
Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
tvOS - update to 16.6
watchOS - update to 9.6 20U73
iPadOS - addressed in versions 15.7.8 19H364, 16.6
Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
tvOS - update to 16.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS