Bug 2246105 (CVE-2023-45664) - CVE-2023-45664 stb: memory access violations
Summary: CVE-2023-45664 stb: memory access violations
Keywords:
Status: NEW
Alias: CVE-2023-45664
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2246106 2246107 2246108
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-10-25 13:05 UTC by ybuenos
Modified: 2023-10-26 01:01 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2023-10-25 13:05:30 UTC
stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_main_outofmem` attempt to double-free the out variable. This happens in `stbi__load_gif_main` because when the `layers * stride` value is zero the behavior is implementation defined, but common that realloc frees the old memory and returns null pointer. Since it attempts to double-free the memory a few lines below the first “free”, the issue can be potentially exploited only in a multi-threaded environment. In the worst case this may lead to code execution.

https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/
https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_image.h#L6993-L6995

Comment 1 ybuenos 2023-10-25 13:07:01 UTC
Created assimp tracking bugs for this issue:

Affects: epel-8 [bug 2246108]


Created stb tracking bugs for this issue:

Affects: epel-all [bug 2246107]
Affects: fedora-all [bug 2246106]

Comment 2 Fedora Update System 2023-10-26 01:01:18 UTC
FEDORA-2023-58af3a2eca has been pushed to the Fedora 40 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.