It was discovered that LLVM Toolchain did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted MLIR file, an attacker could possibly use this issue to cause LLVM Toolchain to crash, resulting in a denial of service. (CVE-2023-29932, CVE-2023-29934, CVE-2023-29939)
It was discovered that LLVM Toolchain did not properly manage memory under
certain circumstances. If a user were tricked into opening a specially
crafted MLIR file, an attacker could possibly use this issue to cause LLVM
Toolchain to crash, resulting in a denial of service. This issue only
affected llvm-toolchain-15. (CVE-2023-29933)
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clang-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clang-13-examples"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clang-format-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clang-tidy-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clang-tools-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "clangd-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libc++-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libc++1-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libc++abi-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libc++abi1-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclang-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclang-common-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclang-cpp13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclang-cpp13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclang1-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclc-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libclc-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libfuzzer-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "liblld-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "liblld-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "liblldb-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "liblldb-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libllvm-13-ocaml-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libllvm13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libmlir-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libmlir-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libomp-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libomp5-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libunwind-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "libunwind-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "lld-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "lldb-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13-dev"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13-examples"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13-linker-tools"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13-runtime"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "llvm-13-tools"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "mlir-13-tools"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "python3-clang-13"
},
{
"binary_version": "1:13.0.1-2ubuntu2.2",
"binary_name": "python3-lldb-13"
}
]
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29932"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29933"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29934"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29939"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clang-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clang-14-examples"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clang-format-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clang-tidy-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clang-tools-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "clangd-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libc++-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libc++1-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libc++abi-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libc++abi1-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclang-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclang-common-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclang-cpp14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclang-cpp14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclang1-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclc-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libclc-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libfuzzer-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "liblld-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "liblld-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "liblldb-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "liblldb-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libllvm-14-ocaml-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libllvm14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libmlir-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libmlir-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libomp-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libomp5-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libunwind-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "libunwind-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "lld-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "lldb-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14-dev"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14-examples"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14-linker-tools"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14-runtime"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "llvm-14-tools"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "mlir-14-tools"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "python3-clang-14"
},
{
"binary_version": "1:14.0.0-1ubuntu1.1",
"binary_name": "python3-lldb-14"
}
]
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29932"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29933"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29934"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29939"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "bolt-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clang-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clang-15-examples"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clang-format-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clang-tidy-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clang-tools-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "clangd-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libbolt-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libc++-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libc++1-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libc++abi-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libc++abi1-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclang-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclang-common-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclang-cpp15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclang-cpp15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclang1-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclc-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libclc-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libfuzzer-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "liblld-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "liblld-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "liblldb-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "liblldb-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libllvm-15-ocaml-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libllvm15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libmlir-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libmlir-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libomp-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libomp5-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libunwind-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "libunwind-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "lld-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "lldb-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15-dev"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15-examples"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15-linker-tools"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15-runtime"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "llvm-15-tools"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "mlir-15-tools"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "python3-clang-15"
},
{
"binary_version": "1:15.0.7-0ubuntu0.22.04.3",
"binary_name": "python3-lldb-15"
}
]
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29932"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29933"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29934"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-29939"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}