Back

MEDIUM

G_variant_byteswap() can take a long time with some non-normal inputs

Published Sep 14, 2023

Description

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

Affected products

Remediation

Red Hat statement

This vulnerability allows for a denial of service attack to be performed against applications that process untrusted GVariant input, compromising application availability by consuming excessive processing time or utilizing a large quantity of memory. The most likely threat is from a local user, which may be possible depending on the configuration of the service and the format of parameters that it expects. While a remote attack is possible if the application is configured to read GVariants over a network connection, this is not the default configuration which makes the likelihood low. Because the most widely available attack vector is local and the consequences are limited to denial of service, Red Hat Product Security rates the impact as Low.

Metrics

References (8)

Change history (4)
  1. MITRE
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H to CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
    • CVSS score changed from 6.5 to 5.5
  2. REDHAT
    • CVSS vector changed from CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H to CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
    • CVSS score changed from 5.5 to 6.5
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 14, 2023
Updated Jun 23, 2026
Reserved May 30, 2023
CISA Vulnrichment
Updated Jun 3, 2025
NVD
Status Modified
Modified Jun 23, 2026
Red Hat
Severity Low
Public date Dec 14, 2022