Ubuntu 22.04 LTS / 23.04:LLVM 工具链漏洞 (USN-6258-1)

medium Nessus 插件 ID 178947

简介

远程 Ubuntu 主机缺少一个或多个安全更新。

描述

远程 Ubuntu 22.04 LTS / 23.04 主机上安装的程序包受到 USN-6258-1 公告中提及的多个漏洞的影响。

- 发现 llvm-project 提交 fdbc55a5 中存在由组件 mlir: : IROperand<mlir: : OpOperand 造成的分段错误。(CVE-2023-29932)

- 发现 llvm-project 提交 bd456297 中存在由组件 mlir: : Block: : getArgument 造成的分段错误。(CVE-2023-29933)

- 发现 llvm-project 提交 6c01b5c 中存在由组件 mlir: : Type: : getDialect() 造成的分段错误。(CVE-2023-29934)

- 发现 llvm-project 提交 a0138390 中存在由组件 mlir: : spirv: : TargetEnv: : TargetEnv(mlir: : spirv: : TargetEnvAttr) 造成的分段错误。(CVE-2023-29939)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

更新受影响的程序包。

另见

https://ubuntu.com/security/notices/USN-6258-1

插件详情

严重性: Medium

ID: 178947

文件名: ubuntu_USN-6258-1.nasl

版本: 1.1

类型: local

代理: unix

发布时间: 2023/7/27

最近更新时间: 2024/8/27

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

风险信息

VPR

风险因素: Low

分数: 3.6

CVSS v2

风险因素: Medium

基本分数: 4.9

时间分数: 3.6

矢量: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS 分数来源: CVE-2023-29939

CVSS v3

风险因素: Medium

基本分数: 5.5

时间分数: 4.8

矢量: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: p-cpe:/a:canonical:ubuntu_linux:libllvm-14-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:lldb-13, p-cpe:/a:canonical:ubuntu_linux:libunwind-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14-dev, p-cpe:/a:canonical:ubuntu_linux:mlir-13-tools, p-cpe:/a:canonical:ubuntu_linux:libclang1-15, p-cpe:/a:canonical:ubuntu_linux:libbolt-15-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-13, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-15-runtime, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-15, p-cpe:/a:canonical:ubuntu_linux:libunwind-13, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libunwind-13-dev, p-cpe:/a:canonical:ubuntu_linux:clang-tools-13, p-cpe:/a:canonical:ubuntu_linux:liblld-15-dev, p-cpe:/a:canonical:ubuntu_linux:lldb-15, p-cpe:/a:canonical:ubuntu_linux:clang-tools-15, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-examples, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-13-dev, p-cpe:/a:canonical:ubuntu_linux:lld-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:clang-14-examples, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-13, p-cpe:/a:canonical:ubuntu_linux:liblld-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev, p-cpe:/a:canonical:ubuntu_linux:bolt-15, p-cpe:/a:canonical:ubuntu_linux:lld-13, p-cpe:/a:canonical:ubuntu_linux:clang-format-15, p-cpe:/a:canonical:ubuntu_linux:clangd-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-15, p-cpe:/a:canonical:ubuntu_linux:llvm-14-tools, cpe:/o:canonical:ubuntu_linux:23.04, p-cpe:/a:canonical:ubuntu_linux:libclang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev, p-cpe:/a:canonical:ubuntu_linux:clang-13, p-cpe:/a:canonical:ubuntu_linux:libllvm-13-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:libpolly-14-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14-examples, p-cpe:/a:canonical:ubuntu_linux:liblldb-14, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-14, p-cpe:/a:canonical:ubuntu_linux:liblldb-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-tools, p-cpe:/a:canonical:ubuntu_linux:libclang1-14, p-cpe:/a:canonical:ubuntu_linux:lld-15, p-cpe:/a:canonical:ubuntu_linux:flang-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-13-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-15-examples, p-cpe:/a:canonical:ubuntu_linux:liblldb-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-14, p-cpe:/a:canonical:ubuntu_linux:libmlir-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14, p-cpe:/a:canonical:ubuntu_linux:llvm-15-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-15, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-13, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-13, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-14, p-cpe:/a:canonical:ubuntu_linux:llvm-13-linker-tools, p-cpe:/a:canonical:ubuntu_linux:libllvm-15-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm64, cpe:/o:canonical:ubuntu_linux:22.04:-:lts, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-13, p-cpe:/a:canonical:ubuntu_linux:libmlir-13, p-cpe:/a:canonical:ubuntu_linux:clang-format-13, p-cpe:/a:canonical:ubuntu_linux:clang-15, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-15, p-cpe:/a:canonical:ubuntu_linux:clang-tools-14, p-cpe:/a:canonical:ubuntu_linux:libclang-common-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-15-dev, p-cpe:/a:canonical:ubuntu_linux:lldb-14, p-cpe:/a:canonical:ubuntu_linux:llvm-15-tools, p-cpe:/a:canonical:ubuntu_linux:libunwind-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-runtime, p-cpe:/a:canonical:ubuntu_linux:clang-13-examples, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-14, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libomp-13-dev, p-cpe:/a:canonical:ubuntu_linux:libllvm13, p-cpe:/a:canonical:ubuntu_linux:libclang-common-14-dev, p-cpe:/a:canonical:ubuntu_linux:libflang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-15-linker-tools, p-cpe:/a:canonical:ubuntu_linux:python3-clang-15, p-cpe:/a:canonical:ubuntu_linux:liblld-14, p-cpe:/a:canonical:ubuntu_linux:libclc-13, p-cpe:/a:canonical:ubuntu_linux:libllvm15, p-cpe:/a:canonical:ubuntu_linux:mlir-14-tools, p-cpe:/a:canonical:ubuntu_linux:clang-format-14, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13, p-cpe:/a:canonical:ubuntu_linux:clang-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-14, p-cpe:/a:canonical:ubuntu_linux:python3-clang-14, p-cpe:/a:canonical:ubuntu_linux:libomp5-15, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp5-13, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-14, p-cpe:/a:canonical:ubuntu_linux:libclang-common-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-14-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-15, p-cpe:/a:canonical:ubuntu_linux:libclang1-13, p-cpe:/a:canonical:ubuntu_linux:clang-15-examples, p-cpe:/a:canonical:ubuntu_linux:clangd-15, p-cpe:/a:canonical:ubuntu_linux:llvm-15, p-cpe:/a:canonical:ubuntu_linux:liblld-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm64, p-cpe:/a:canonical:ubuntu_linux:libclc-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13, p-cpe:/a:canonical:ubuntu_linux:libmlir-15, p-cpe:/a:canonical:ubuntu_linux:llvm-14-linker-tools, p-cpe:/a:canonical:ubuntu_linux:libpolly-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14-runtime, p-cpe:/a:canonical:ubuntu_linux:mlir-15-tools, p-cpe:/a:canonical:ubuntu_linux:libclang-14-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-15-dev, p-cpe:/a:canonical:ubuntu_linux:clangd-13, p-cpe:/a:canonical:ubuntu_linux:libomp5-14, p-cpe:/a:canonical:ubuntu_linux:libunwind-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclc-13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-dev, p-cpe:/a:canonical:ubuntu_linux:python3-clang-13, p-cpe:/a:canonical:ubuntu_linux:liblld-13, p-cpe:/a:canonical:ubuntu_linux:libllvm14, p-cpe:/a:canonical:ubuntu_linux:libmlir-13-dev

必需的 KB 项: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release

易利用性: No known exploits are available

补丁发布日期: 2023/7/27

漏洞发布日期: 2023/5/5

参考资料信息

CVE: CVE-2023-29932, CVE-2023-29933, CVE-2023-29934, CVE-2023-29939

USN: 6258-1