cbcvebase.
CVE-2023-5156
published 2023-09-25

CVE-2023-5156: A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.37-11 (forky)glibc 2.37-11 (forky)
gnuglibc>= 0 < 2.37-112.37-11
gnuglibc>= 0 < 2.37-112.37-11
gnuglibc>= 0 < 2.31-0ubuntu9.142.31-0ubuntu9.14
gnuglibc>= 0 < 2.35-0ubuntu3.62.35-0ubuntu3.6
gnuglibc>= 0 < 2.35-0ubuntu3.52.35-0ubuntu3.5
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm52.23-0ubuntu11.3+esm5
gnuglibc>= 0 < 2.27-3ubuntu1.6+esm12.27-3ubuntu1.6+esm1
gnuglibc>= 2.34 < 2.392.39
msrcazl3_glibc_2.38-10_on_azure_linux_3.0
msrcazl3_glibc_2.38-6_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_glibc_2.35-6_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM