Memory leak in GNU C Library (glibc) - CVE-2023-5156
Published: October 3, 2023
Vulnerability identifier: #VU81448
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5156
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak caused by an incorrect fix for #VU81447 (CVE-2023-4806). A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
GNU C Library (glibc)
Gentoo Linux
Amazon Linux AMI
Ubuntu
openEuler
Anolis OS
libc-bin (Ubuntu package)
libc6 (Ubuntu package)
nss_modules
libnsl
nscd
glibc-debugsource
glibc-locale-source
glibc-debuginfo
glibc-debugutils
glibc-compat-2.17
glibc
glibc-devel
glibc-all-langpacks
glibc-benchtests
glibc-nss-devel
glibc-common
glibc-help
nscd (Ubuntu package)
glibc-gconv-extra
glibc-langpack-en
glibc-langpack-zh
glibc-minimal-langpack
glibc-static
glibc-utils
nss_db
nss_hesiod
glibc-doc
compat-libpthread-nonshared
sys-libs/glibc
IBM Integrated Analytics System
Cloud Pak for Network Automation
Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Juniper Cloud Native Router
Junos cRPD
Gentoo Linux
Amazon Linux AMI
Ubuntu
openEuler
Anolis OS
libc-bin (Ubuntu package)
libc6 (Ubuntu package)
nss_modules
libnsl
nscd
glibc-debugsource
glibc-locale-source
glibc-debuginfo
glibc-debugutils
glibc-compat-2.17
glibc
glibc-devel
glibc-all-langpacks
glibc-benchtests
glibc-nss-devel
glibc-common
glibc-help
nscd (Ubuntu package)
glibc-gconv-extra
glibc-langpack-en
glibc-langpack-zh
glibc-minimal-langpack
glibc-static
glibc-utils
nss_db
nss_hesiod
glibc-doc
compat-libpthread-nonshared
sys-libs/glibc
IBM Integrated Analytics System
Cloud Pak for Network Automation
Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2023-5156
Install updates from vendor's website.
libc-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 2.31-0ubuntu9.14, 2.35-0ubuntu3.5, 2.35-0ubuntu3.6, 2.37-0ubuntu2.2
libc6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.31-0ubuntu9.14, 2.35-0ubuntu3.5, 2.35-0ubuntu3.6, 2.37-0ubuntu2.2
IBM Integrated Analytics System - update to 1.0.30.0
Cloud Pak for Network Automation - update to 2.6.4
nss_modules - update to 2.28-97
libnsl - update to 2.28-97
nscd - update to 2.28-97
glibc-debugsource - update to 2.28-97
glibc-locale-source - update to 2.28-97
glibc-debuginfo - update to 2.28-97
glibc-debugutils - update to 2.28-97
glibc-compat-2.17 - update to 2.28-97
glibc - update to 2.28-97
glibc-devel - update to 2.28-97
glibc-all-langpacks - update to 2.28-97
glibc-benchtests - update to 2.28-97
glibc-nss-devel - update to 2.28-97
glibc-common - update to 2.28-97
glibc-help - update to 2.28-97
glibc - update to 2.34-52
nscd (Ubuntu package) - update to 2.35-0ubuntu3.6
libnsl - update to 2.36-10
glibc-gconv-extra - update to 2.36-10
glibc-langpack-en - update to 2.36-10
glibc-langpack-zh - update to 2.36-10
glibc-locale-source - update to 2.36-10
glibc-minimal-langpack - update to 2.36-10
glibc-nss-devel - update to 2.36-10
glibc-static - update to 2.36-10
glibc-utils - update to 2.36-10
glibc-benchtests - update to 2.36-10
nss_db - update to 2.36-10
nss_hesiod - update to 2.36-10
glibc-doc - update to 2.36-10
glibc-devel - update to 2.36-10
glibc-common - update to 2.36-10
glibc-all-langpacks - update to 2.36-10
glibc - update to 2.36-10
compat-libpthread-nonshared - update to 2.36-10
sys-libs/glibc - update to 2.38-r10
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop - update to 5.0.3
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
libc6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.31-0ubuntu9.14, 2.35-0ubuntu3.5, 2.35-0ubuntu3.6, 2.37-0ubuntu2.2
IBM Integrated Analytics System - update to 1.0.30.0
Cloud Pak for Network Automation - update to 2.6.4
nss_modules - update to 2.28-97
libnsl - update to 2.28-97
nscd - update to 2.28-97
glibc-debugsource - update to 2.28-97
glibc-locale-source - update to 2.28-97
glibc-debuginfo - update to 2.28-97
glibc-debugutils - update to 2.28-97
glibc-compat-2.17 - update to 2.28-97
glibc - update to 2.28-97
glibc-devel - update to 2.28-97
glibc-all-langpacks - update to 2.28-97
glibc-benchtests - update to 2.28-97
glibc-nss-devel - update to 2.28-97
glibc-common - update to 2.28-97
glibc-help - update to 2.28-97
glibc - update to 2.34-52
nscd (Ubuntu package) - update to 2.35-0ubuntu3.6
libnsl - update to 2.36-10
glibc-gconv-extra - update to 2.36-10
glibc-langpack-en - update to 2.36-10
glibc-langpack-zh - update to 2.36-10
glibc-locale-source - update to 2.36-10
glibc-minimal-langpack - update to 2.36-10
glibc-nss-devel - update to 2.36-10
glibc-static - update to 2.36-10
glibc-utils - update to 2.36-10
glibc-benchtests - update to 2.36-10
nss_db - update to 2.36-10
nss_hesiod - update to 2.36-10
glibc-doc - update to 2.36-10
glibc-devel - update to 2.36-10
glibc-common - update to 2.36-10
glibc-all-langpacks - update to 2.36-10
glibc - update to 2.36-10
compat-libpthread-nonshared - update to 2.36-10
sys-libs/glibc - update to 2.38-r10
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop - update to 5.0.3
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
External References
Related Security Bulletins
- Memory leak in GNU C Library
- Ubuntu update for glibc
- Ubuntu update for glibc
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Gentoo update for glibc
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- openEuler update for glibc
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- IBM Integrated Analytics System update for glibc
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- Amazon Linux AMI update for glibc
- Anolis OS update for glibc