Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Gentoo: GLSA-202505-05 High: Orc Arbitrary Execution Risk

gentoo
Calendar Grey May 12, 2025
Dist Gentoo Esm H88
The Gentoo Linux Security Advisory GLSA 202505-06 highlights a critical vulnerability in Gnome which permits unauthorized access to sensitive data.
A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Summary

Please review the CVE identifier referenced below for details.

Resolution

All Orc users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-lang/orc-0.4.40"

References

[ 1 ] CVE-2024-40897 https://nvd.nist.gov/vuln/detail/CVE-2024-40897

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
https://security.gentoo.org/glsa/202505-05
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: High
Title: Orc: Arbitrary Code Execution
Date: May 12, 2025
Bugs: #937127
ID: 202505-05

Synopsis

A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Background

Orc is a library and set of tools for compiling and executing very simple programs that operate on arrays of data. The "language" is a generic assembly language that represents many of the features available in SIMD architectures, including saturated addition and subtraction, and many arithmetic operations.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Package Vulnerable Unaffected ------------ ------------ ------------ dev-lang/orc < 0.4.40 >= 0.4.40

Impact

It is possible for a malicious third party to trigger a buffer overflow and effect code execution with the same privileges as the orc compiler is called with by feeding it with malformed orc source files.
This only affects developers and CI environments using orcc, not users of liborc.

Workaround

There is no known workaround at this time.

Related News

Your message here