Back to bug 2211833

Who When What Removed Added
Dhananjay Arunesh 2023-06-05 04:23:57 UTC CC mcatanza, mdean, rh-spice-bugs, virt-maint, walters
Dhananjay Arunesh 2023-06-06 07:25:54 UTC Depends On 2212725, 2212727, 2212724, 2212722
Dhananjay Arunesh 2023-06-06 07:26:02 UTC Depends On 2212720, 2212728, 2212723, 2212721, 2212726
Red Hat Bugzilla 2023-07-07 08:31:02 UTC Assignee security-response-team nobody
Pedro Sampaio 2023-07-20 20:23:37 UTC Doc Text GLib's GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499
RaTasha Tillery-Smith 2023-07-21 13:41:10 UTC Doc Text GLib's GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499 A flaw was found in Glib, where the GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499.
Pedro Sampaio 2023-07-24 15:13:29 UTC Summary CVE-2023-32636 glib: fuzz_variant_text: Timeout in fuzz_variant_text CVE-2023-32636 glib: Timeout in fuzz_variant_text
Pedro Sampaio 2023-07-27 13:56:08 UTC Doc Text A flaw was found in Glib, where the GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499. A flaw was found in glib, where the "GVariant" de serialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
Pedro Sampaio 2023-07-27 13:56:31 UTC Doc Text A flaw was found in glib, where the "GVariant" de serialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499. A flaw was found in glib, where the gvariant de serialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
Pedro Sampaio 2023-07-27 13:56:51 UTC Doc Text A flaw was found in glib, where the gvariant de serialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499. A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

Back to bug 2211833