ALSA-2023:6631
Dashboard / Vulnerabilities / ALSA-2023:6631
ALSA-2023:6631
Summary: Low: glib2 security and bug fix update
Details: GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: GVariant offset table entry size is not checked in is_normal() (CVE-2023-29499) * glib: g_variant_byteswap() can take a long time with some non-normal inputs (CVE-2023-32611) * glib: GVariant deserialisation does not match spec for non-normal data (CVE-2023-32665) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://access.redhat.com/errata/RHSA-2023:6631, https://access.redhat.com/security/cve/CVE-2023-29499, https://access.redhat.com/security/cve/CVE-2023-32611, https://access.redhat.com/security/cve/CVE-2023-32665, https://bugzilla.redhat.com/2211827, https://bugzilla.redhat.com/2211828, https://bugzilla.redhat.com/2211829, https://errata.almalinux.org/9/ALSA-2023-6631.html
Affected packages
Package
Name: glib2
Purl: pkg:rpm/almalinux/glib2
Affected ranges
Type: ECOSYSTEM
Events:
