wiki/docs/issues/CVE-2024-2961.md

1.3 KiB

CVE-2024-2961: glibc

Title

CVE-2024-2961: glibc: Out of bounds write in iconv may lead to remote code execution

Summary

As described by Red Hat:

An out-of-bounds write flaw was found in the ISO-2022-CN-EXT plugin for glibc's iconv library. When converting from UCS4 charset, adding certain escape charterers is required to indicate where the charset was changed to the library. During this process, iconv improperly checks the boundaries of internal buffers, leading to a buffer overflow, which allows writing up to 3 bytes outside the desired memory location. This issue may allow an attacker to craft a malicious characters sequence that will trigger the out-of-bounds write and perform remote code execution, presenting a high impact to the Integrity, Confidentiality, and Availability triad.

and as further discussed on oss-security:

On PHP [this glibc bug led] to amazing results: a new exploitation technique that affects the whole PHP ecosystem.

Public disclosure date: April 17, 2024

EL9

Fixed in version: 2.34-83.12.el9_3.security.0.5 available April 18, 2024

EL8

Affected. We will of course rebuild upstream's fix as soon as it arrives.