CVE-2016-6323
Summary
| CVE | CVE-2016-6323 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-10-07 14:59:00 UTC |
| Updated | 2023-11-07 02:33:00 UTC |
| Description | The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 23 Update: glibc-2.22-18.fc23 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| sourceware.org Git - glibc.git/commit |
CONFIRM |
sourceware.org |
Issue Tracking, Patch |
| openSUSE-SU-2016:2443-1: moderate: Security update for glibc |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| [SECURITY] Fedora 24 Update: glibc-2.23.1-10.fc24 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - CVE-2016-6323: Missing unwind information on ARM EABI (32-bit) causes
backtrace generation to hang |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| 20435 – (CVE-2016-6323) Missing unwind info in __startcontext causes infinite loop in _Unwind_Backtrace (CVE-2016-6323) |
CONFIRM |
sourceware.org |
Issue Tracking |
| sourceware.org Git - glibc.git/commit |
|
sourceware.org |
|
| GNU glibc CVE-2016-6323 Infinite Loop Denial of Service Vulnerability |
BID |
www.securityfocus.com |
|
| [SECURITY] Fedora 23 Update: glibc-2.22-18.fc23 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 25 Update: glibc-2.24-3.fc25 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| GNU C Library: Multiple vulnerabilities (GLSA 201706-19) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| IBM Security Bulletin: Vulnerabilities in OpenSSL, OpenVPN and GNU glibc affect IBM Security Virtual Server Protection for VMware - United States |
CONFIRM |
www-01.ibm.com |
|
| [SECURITY] Fedora 25 Update: glibc-2.24-3.fc25 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 24 Update: glibc-2.23.1-10.fc24 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 670286 EulerOS Security Update for glibc (EulerOS-SA-2021-1790)
- 670842 EulerOS Security Update for glibc (EulerOS-SA-2021-1790)