Integer overflow in GNU C Library (glibc) - CVE-2023-6780
Published: January 31, 2024 / Updated: May 20, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow within the __vsyslog_internal() function. A local user can pass specially crafted input to the affected application, trigger an integer overflow and execute arbitrary code with elevated privileges.
Affected software
Gentoo Linux
Debian Linux
Anolis OS
Ubuntu
Fedora
glibc (Debian package)
glibc-gconv-extra
glibc-doc
nss_hesiod
nss_db
libnsl
glibc-utils
glibc-static
glibc-nss-devel
glibc-minimal-langpack
glibc-locale-source
glibc-langpack-zh
glibc-langpack-en
glibc-devel
glibc-common
glibc-benchtests
glibc-all-langpacks
glibc
compat-libpthread-nonshared
sys-libs/glibc
libc6 (Ubuntu package)
iDRAC9
Precision 7920 Rack
Precision 7920 XL Rack
How to mitigate CVE-2023-6780
glibc-gconv-extra - update to 2.36-13
glibc-doc - update to 2.36-13
nss_hesiod - update to 2.36-13
nss_db - update to 2.36-13
libnsl - update to 2.36-13
glibc-utils - update to 2.36-13
glibc-static - update to 2.36-13
glibc-nss-devel - update to 2.36-13
glibc-minimal-langpack - update to 2.36-13
glibc-locale-source - update to 2.36-13
glibc-langpack-zh - update to 2.36-13
glibc-langpack-en - update to 2.36-13
glibc-devel - update to 2.36-13
glibc-common - update to 2.36-13
glibc-benchtests - update to 2.36-13
glibc-all-langpacks - update to 2.36-13
glibc - update to 2.36-13
compat-libpthread-nonshared - update to 2.36-13
glibc - addressed in versions 2.37-18.fc38, 2.38-16.fc39
sys-libs/glibc - update to 2.38-r10
libc6 (Ubuntu package) - update to 2.38-1ubuntu6.1
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
Precision 7920 XL Rack - update to 7.00.00.181