CVE-2023-29499
published 2023-09-14CVE-2023-29499: A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.77%
51.4th percentile
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.74.4-1 (bookworm) | glib2.0 2.74.4-1 (bookworm) |
| debian | glib2.0 | — | — |
| glib | glib | — | — |
| gnome | glib | < 2.74.4 | 2.74.4 |
| msrc | cbl2_glib_2.71.0-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79g9-vx8c-xfmq: A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added
ghsa_unreviewed·2023-09-14·CVSS 5.5
CVE-2023-32636 [MEDIUM] CWE-400 GHSA-79g9-vx8c-xfmq: A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
GHSA
GHSA-794g-pjcw-ggfp: A flaw was found in GLib
ghsa_unreviewed·2023-09-14
CVE-2023-29499 [HIGH] CWE-400 GHSA-794g-pjcw-ggfp: A flaw was found in GLib
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
OSV
CVE-2023-29499: A flaw was found in GLib
osv·2023-09-14·CVSS 7.5
CVE-2023-29499 [HIGH] CVE-2023-29499: A flaw was found in GLib
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
OSV
CVE-2023-32636: A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added
osv·2023-06-07·CVSS 7.5
CVE-2023-32636 [HIGH] CVE-2023-32636: A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2023-10-19
CVE-2023-29499 GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-6165-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu
18.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled non-normal GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or perform other unknown attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table valid
vendor_msrc·2023-09-12·CVSS 4.7
CVE-2023-32636 [MEDIUM] CWE-400 A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table valid
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
Microsoft
Gvariant offset table entry size is not checked in is_normal()
vendor_msrc·2023-09-12·CVSS 5.5
CVE-2023-29499 [MEDIUM] CWE-400 Gvariant offset table entry size is not checked in is_normal()
Gvariant offset table entry size is not checked in is_normal()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2023-06-14
CVE-2023-32636 GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled non-normal GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a denial
of service, or perform other unknown attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-29499: glib2.0 - A flaw was found in GLib. GVariant deserialization fails to validate that the in...
vendor_debian·2023·CVSS 5.5
CVE-2023-29499 [MEDIUM] CVE-2023-29499: glib2.0 - A flaw was found in GLib. GVariant deserialization fails to validate that the in...
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Scope: local
bookworm: resolved (fixed in 2.74.4-1)
bullseye: resolved (fixed in 2.66.8-1+deb11u1)
forky: resolved (fixed in 2.74.4-1)
sid: resolved (fixed in 2.74.4-1)
trixie: resolved (fixed in 2.74.4-1)
Debian
CVE-2023-32636: glib2.0 - A flaw was found in glib, where the gvariant deserialization code is vulnerable ...
vendor_debian·2023·CVSS 5.5
CVE-2023-32636 [MEDIUM] CVE-2023-32636: glib2.0 - A flaw was found in glib, where the gvariant deserialization code is vulnerable ...
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
glib: GVariant offset table entry size is not checked in is_normal()
vendor_redhat·2022-12-14·CVSS 5.5
CVE-2023-29499 [MEDIUM] CWE-502 glib: GVariant offset table entry size is not checked in is_normal()
glib: GVariant offset table entry size is not checked in is_normal()
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Statement: This vulnerability allows for a denial of service attack to be performed against applications that process untrusted GVariant input, compromising application availability by consuming excessive processing time or utilizing a large quantity of memory. The most likely threat is from a local user, which may be possible depending on the configuration of the service and the format of parameters that it expects. While a remot
Red Hat
glib: Timeout in fuzz_variant_text
vendor_redhat·2022-12-14·CVSS 5.5
CVE-2023-32636 [MEDIUM] CWE-400 glib: Timeout in fuzz_variant_text
glib: Timeout in fuzz_variant_text
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers t
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-32636 glib: Timeout in fuzz_variant_text
bugzilla·2023-06-02·CVSS 7.5
CVE-2023-32636 [HIGH] CVE-2023-32636 glib: Timeout in fuzz_variant_text
CVE-2023-32636 glib: Timeout in fuzz_variant_text
GLib's GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499
References:
https://gitlab.gnome.org/GNOME/glib/-/issues/2841
Discussion:
Created glib tracking bugs for this issue:
Affects: epel-all [bug 2212720]
Created glib2 tracking bugs for this issue:
Affects: fedora-37 [bug 2212721]
Affects: fedora-38 [bug 2212726]
Created mingw-glib2 tracking bugs for this issue:
Affects: fedora-37 [bug 2212723]
Affects: fedora-38 [b
Bugzilla
CVE-2023-29499 glib: GVariant offset table entry size is not checked in is_normal()
bugzilla·2023-06-02·CVSS 7.5
CVE-2023-29499 [HIGH] CVE-2023-29499 glib: GVariant offset table entry size is not checked in is_normal()
CVE-2023-29499 glib: GVariant offset table entry size is not checked in is_normal()
GLib's GVariant deserialization prior to GLib 2.74.4 failed to validate the input conforms to the expected format, leading to denial of service.
Referenves:
https://gitlab.gnome.org/GNOME/glib/-/issues/2794
Discussion:
Created glib tracking bugs for this issue:
Affects: epel-all [bug 2212699]
Created glib2 tracking bugs for this issue:
Affects: fedora-37 [bug 2212700]
Affects: fedora-38 [bug 2212704]
Created mingw-glib2 tracking bugs for this issue:
Affects: fedora-37 [bug 2212701]
Affects: fedora-38 [bug 2212707]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2023:6631 https://access.redhat.com/errata/RHSA-2023:6631
---
This vulnerability a
https://access.redhat.com/security/cve/CVE-2023-29499https://bugzilla.redhat.com/show_bug.cgi?id=2211828https://gitlab.gnome.org/GNOME/glib/-/issues/2794https://lists.debian.org/debian-lts-announce/2023/09/msg00030.htmlhttps://security.gentoo.org/glsa/202311-18https://security.netapp.com/advisory/ntap-20231103-0001/https://access.redhat.com/security/cve/CVE-2023-29499https://bugzilla.redhat.com/show_bug.cgi?id=2211828https://gitlab.gnome.org/GNOME/glib/-/issues/2794https://lists.debian.org/debian-lts-announce/2023/09/msg00030.htmlhttps://security.gentoo.org/glsa/202311-18https://security.netapp.com/advisory/ntap-20231103-0001/
2023-09-14
Published