CVE-2023-4527

medium
Published 2023-10-05 · Modified 2023-10-06
CVSS v3
6.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS v2
VIR risk
6.5

Description

Important: glibc security update

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5453.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5455.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2238352

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237798

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237782

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2234712

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5455

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-4527

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-4527.html

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5455

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5453

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
debian debianbookwormfixed2.36-9+deb12u3
debian debianbullseyefixed0
debian debianforkyfixed2.37-9
debian debiansidfixed2.37-9
debian debiantrixiefixed2.37-9
fedora fedora37affected
fedora fedora38affected
fedora fedora39affected
redhat rhel8.0affected
redhat rhel9.0affected
redhat rhel8.8affected
redhat rhel9.2affected
redhat rhel9.0_aarch64affected

Application impact

VendorProductVersionsFixed
gnuglibc{"startIncluding":"2.36","endExcluding":"2.36.113"}2.36.113
redhatcodeready_linux_builder_eus9.2
redhatcodeready_linux_builder_eus_for_power_little_endian9.0_ppc64le
redhatcodeready_linux_builder_eus_for_power_little_endian_eus9.2_ppc64le
redhatcodeready_linux_builder_for_arm649.0_aarch64
redhatcodeready_linux_builder_for_arm64_eus9.2_aarch64
redhatcodeready_linux_builder_for_ibm_z_systems9.0_s390x
redhatcodeready_linux_builder_for_ibm_z_systems_eus9.2_s390x

References

CWEs

CWE-121 CWE-125

Verify integrity in audit chain (admin only). AS-IS.