cbcvebase.
CVE-2023-4039
published 2023-09-13

CVE-2023-4039: **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in…

PriorityP426medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.67%
47.5th percentile
**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized local variables or those created using alloca(). The stack-protector operates as intended for statically-sized local variables. The default behavior when the stack-protector detects an overflow is to terminate your application, resulting in controlled loss of availability. An attacker who can exploit a buffer overflow without triggering the stack-protector might be able to change program flow control to cause an uncontrolled loss of availability or to go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.

Affected

19 ranges
VendorProductVersion rangeFixed in
arm_ltdarm_gnu_toolchain
debiangcc-10< gcc-11 11.4.0-4 (sid)gcc-11 11.4.0-4 (sid)
debiangcc-11< gcc-11 11.4.0-4 (sid)gcc-11 11.4.0-4 (sid)
debiangcc-12< gcc-11 11.4.0-4 (sid)gcc-11 11.4.0-4 (sid)
debiangcc-13< gcc-11 11.4.0-4 (sid)gcc-11 11.4.0-4 (sid)
debiangcc-9< gcc-11 11.4.0-4 (sid)gcc-11 11.4.0-4 (sid)
gnugcc< 2023-09-122023-09-12
gnugcc
gnugcc>= 0 < 13.2.1_git20231014-r013.2.1_git20231014-r0
gnugcc>= 0 < 13.2.1_git20231014-r013.2.1_git20231014-r0
gnugcc>= 0 < 13.2.1_git20231014-r013.2.1_git20231014-r0
gnugcc>= 0 < 13.2.1_git20231014-r013.2.1_git20231014-r0
gnugcc>= 0 < 13.2.1_git20231014-r013.2.1_git20231014-r0
msrcazl3_gcc_13.2.0-7_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_gcc_11.2.0-6_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_msrc4.8MEDIUM
vendor_oracle4.8MEDIUM
vendor_redhat4.8MEDIUM
vendor_ubuntu4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.