"Critical Root Access Flaw Discovered in Glibc Library on Major Linux Distros"

1 min read
Source: The Hacker News
"Critical Root Access Flaw Discovered in Glibc Library on Major Linux Distros"
Photo: The Hacker News
TL;DR

A new security flaw in the GNU C library (glibc) allows local attackers to gain root access on Linux machines, impacting major distributions like Debian, Ubuntu, and Fedora. The vulnerability, tracked as CVE-2023-6246, is a heap-based buffer overflow in the __vsyslog_internal() function and was accidentally introduced in glibc 2.37. Further analysis also revealed two more flaws in the same function and a bug in the qsort() function, affecting all glibc versions released since 1992. This comes after a previous high-severity flaw in glibc was detailed by Qualys, emphasizing the critical need for strict security measures in software development.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News