libcap: Memory Leak on pthread_create() Error
Published Jun 6, 2023
3.3
LOWCVSS 3.1
EPSS 0.35%
Description
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
Affected products
- Vendor n/a Product Libcap Defaultn/a
- Version NAStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Libcap | n/a |
|
Configuration 1
- 2.66
Configuration 2
- 6.0
- 7.0
- 8.0
- 9.0
Configuration 3
- 10.0
- 11.0
- 12.0
Configuration 4
- 37
- 38
No data.
Red Hat Enterprise Linux 8
libcap-0:2.48-5.el8_8
Fixed · RHSA-2023:4524
Red Hat Enterprise Linux 8.6 Extended Update Support
libcap-0:2.48-4.el8_6
Fixed · RHSA-2023:7400
Red Hat Enterprise Linux 9
libcap-0:2.48-9.el9_2
Fixed · RHSA-2023:5071
Red Hat Enterprise Linux 9
libcap-0:2.48-9.el9_2
Fixed · RHSA-2023:5071
Red Hat Enterprise Linux 6
compat-libcap1
Out of support scope
Red Hat Enterprise Linux 6
libcap
Out of support scope
Red Hat Enterprise Linux 7
compat-libcap1
Out of support scope
Red Hat Enterprise Linux 7
libcap
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libcap-0:2.48-5.el8_8 | Fixed | RHSA-2023:4524 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | libcap-0:2.48-4.el8_6 | Fixed | RHSA-2023:7400 |
| Red Hat Enterprise Linux 9 | libcap-0:2.48-9.el9_2 | Fixed | RHSA-2023:5071 |
| Red Hat Enterprise Linux 9 | libcap-0:2.48-9.el9_2 | Fixed | RHSA-2023:5071 |
| Red Hat Enterprise Linux 6 | compat-libcap1 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libcap | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-libcap1 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libcap | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-2602 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2209114 Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZ57ICDLMVYEREXQGZWL4GWI7FRJCRQT/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPEGCFMCN5KGCFX5Y2VTKR732TTD4ADW/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2602
- https://www.cve.org/CVERecord?id=CVE-2023-2602
- https://www.x41-dsec.de/static/reports/X41-libcap-Code-Review-2023-OSTIF-Final-Report.pdf ExploitTechnical Description
Change history (0)
No recorded changes yet.