USN-6258-1
Dashboard / Vulnerabilities / USN-6258-1
USN-6258-1
Summary: llvm-toolchain-13, llvm-toolchain-14, llvm-toolchain-15 vulnerabilities
Details: It was discovered that LLVM Toolchain did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted MLIR file, an attacker could possibly use this issue to cause LLVM Toolchain to crash, resulting in a denial of service. (CVE-2023-29932, CVE-2023-29934, CVE-2023-29939) It was discovered that LLVM Toolchain did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted MLIR file, an attacker could possibly use this issue to cause LLVM Toolchain to crash, resulting in a denial of service. This issue only affected llvm-toolchain-15. (CVE-2023-29933)
References: https://ubuntu.com/security/notices/USN-6258-1, https://ubuntu.com/security/CVE-2023-29932, https://ubuntu.com/security/CVE-2023-29933, https://ubuntu.com/security/CVE-2023-29934, https://ubuntu.com/security/CVE-2023-29939
Affected packages
Package
Name: llvm-toolchain-13
Purl: pkg:deb/ubuntu/llvm-toolchain-13@1:13.0.1-2ubuntu2.2?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
