Wind River Support Network

HomeDefectsLIN1021-7167
Fixed

LIN1021-7167 : Security Advisory - glibc - CVE-2023-6246

Created: Jan 30, 2024    Updated: Feb 9, 2024
Resolved Date: Feb 8, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.

https://nvd.nist.gov/vuln/detail/CVE-2023-6246
Live chat
Online