VDB

DEBIAN-CVE-2023-4039

DEBIAN-CVE-2023-4039 PUBLISHED CVSS 4.800000190734863 MEDIUM

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized local variables or those created using alloca(). The stack-protector operates as intended for statically-sized local variables. The default behavior when the stack-protector detects an overflow is to terminate your application, resulting in controlled loss of availability. An attacker who can exploit a buffer overflow without triggering the stack-protector might be able to change program flow control to cause an uncontrolled loss of availability or to go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:12gcc-120, 12.2.0-14, 0
Debian:12gcc-1111.3.0-13, 11.3.0-14, 11.3.0-15
Debian:11gcc-1010.2.1-16, 10.3.0-16, 10.3.0-2
Debian:14gcc-120, 0, 0
Debian:13gcc-130, 0, 0
Debian:13gcc-120, 0, 0
Debian:11gcc-99.5.0-4, 9.5.0-5, 9.5.0-6
Debian:14gcc-130, 0, 0

Timeline

  • Sep 13, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›