Bug 2214914 (CVE-2023-34241)
Summary: | CVE-2023-34241 cups: use-after-free in cupsdAcceptClient() in scheduler/client.c | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Nobody <nobody> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | chazlett, zdohnal |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A vulnerability was found in CUPS. This issue occurs due to logging data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data immediately before the connection closed, resulting in a use-after-free in cupsdAcceptClient() in scheduler/client.c
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2214915, 2214917, 2216717, 2216718 | ||
Bug Blocks: | 2214604 |
Description
Sandipan Roy
2023-06-14 04:51:21 UTC
Created cups tracking bugs for this issue: Affects: fedora-37 [bug 2216717] Affects: fedora-38 [bug 2216718] This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6596 https://access.redhat.com/errata/RHSA-2023:6596 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7165 https://access.redhat.com/errata/RHSA-2023:7165 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:1101 https://access.redhat.com/errata/RHSA-2024:1101 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:1409 https://access.redhat.com/errata/RHSA-2024:1409 |