A buffer overflow vulnerability has been found in GMP which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202309-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GMP: Buffer Overflow Vulnerability Date: September 29, 2023 Bugs: #823804 ID: 202309-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A buffer overflow vulnerability has been found in GMP which could result in denial of service. Background ========== The GNU Multiple Precision Arithmetic Library is a library forarbitrary- precision arithmetic on different types of numbers. Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ dev-libs/gmp < 6.2.1-r2 > = 6.2.1-r2 Description =========== There is an integer overflow leading to a buffer overflow when processing untrusted input via GMP's mpz_inp_raw function. Impact ====== Untrusted input can cause a denial of service via segmentation fault. Workaround ========== Users can ensure no untrusted input is passed into GMP's mpz_inp_raw function. Resolution ========== All GMP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/gmp-6.2.1-r2" References ========== [ 1 ] CVE-2021-43618 https://nvd.nist.gov/vuln/detail/CVE-2021-43618 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202309-13 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should beaddressed to
GMP could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5672-2 March 06, 2023 gmp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM Summary: GMP could be made to crash if it received specially crafted input. Software Description: - gmp: Multiprecision arithmetic library developers tools Details: USN-5672-1 fixed a vulnerability in GMP. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that GMP did not properly manage memory on 32-bit platforms when processing a specially crafted input. An attacker could possibly use this issue to cause applications using GMP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: libgmp-dev 2:5.1.3+dfsg-1ubuntu1+esm1 libgmp10 2:5.1.3+dfsg-1ubuntu1+esm1 libgmpxx4ldbl 2:5.1.3+dfsg-1ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5672-2 https://ubuntu.com/security/notices/USN-5672-1 CVE-2021-43618 . A vulnerability in GMP may lead to a system failure when processing specially designed input, impacting Ubuntu 14.04 ESM users. Update now for the necessary patch.. GMP Crash, Ubuntu Update, Denial Of Service. . LinuxSecurity.com Team
GMP could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5672-1 October 12, 2022 GMP vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: GMP could be made to crash if it received specially crafted input. Software Description: - gmp: Multiprecision arithmetic library developers tools Details: It was discovered that GMP did not properly manage memory on 32-bit platforms when processing a specially crafted input. An attacker could possibly use this issue to cause applications using GMP to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libgmp-dev 2:6.2.0+dfsg-4ubuntu0.1 libgmp10 2:6.2.0+dfsg-4ubuntu0.1 libgmpxx4ldbl 2:6.2.0+dfsg-4ubuntu0.1 Ubuntu 18.04 LTS: libgmp-dev 2:6.1.2+dfsg-2ubuntu0.1 libgmp10 2:6.1.2+dfsg-2ubuntu0.1 libgmpxx4ldbl 2:6.1.2+dfsg-2ubuntu0.1 Ubuntu 16.04 ESM: libgmp-dev 2:6.1.0+dfsg-2ubuntu0.1~esm1 libgmp10 2:6.1.0+dfsg-2ubuntu0.1~esm1 libgmpxx4ldbl 2:6.1.0+dfsg-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5672-1 CVE-2021-43618 Package Information: https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1 . A newly discovered bug in GMP poses risks of system failures on Fedora. Users using affected versions should apply updates promptly.. GMP Denial Of Service, Ubuntu Security Advisory, Update Recommendations, Software Management. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gmp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1569-1 Rating: moderate References: #1192717 Cross-References: CVE-2021-43618 CVSS scores: CVE-2021-43618 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-43618 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1569=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): gmp-debugsource-6.1.2-lp152.6.6.1 gmp-devel-6.1.2-lp152.6.6.1 libgmp10-6.1.2-lp152.6.6.1 libgmp10-debuginfo-6.1.2-lp152.6.6.1 libgmpxx4-6.1.2-lp152.6.6.1 libgmpxx4-debuginfo-6.1.2-lp152.6.6.1 - openSUSE Leap 15.2 (x86_64): gmp-devel-32bit-6.1.2-lp152.6.6.1 libgmp10-32bit-6.1.2-lp152.6.6.1 libgmp10-32bit-debuginfo-6.1.2-lp152.6.6.1 libgmpxx4-32bit-6.1.2-lp152.6.6.1 libgmpxx4-32bit-debuginfo-6.1.2-lp152.6.6.1 References: https://www.suse.com/security/cve/CVE-2021-43618.html https://bugzilla.suse.com/1192717 . The openSUSE Security Update mitigates a buffer overflow vulnerability in gmp, classified with moderate severity, and includesdetailed patch guidance.. openSUSE Update, gmp Security Patch, Buffer Overflow Fix, Software Updates. . Severity: Important. LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:573-1 Container Tags : suse/sle15:15.3 , suse/sle15:15.3.17.8.41 Container Release : 17.8.41 Severity : moderate Type : security References : 1192717 CVE-2021-43618 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:3946-1 Released: Mon Dec 6 14:57:42 2021 Summary: Security update for gmp Type: security Severity: moderate References: 1192717,CVE-2021-43618 This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). The following package changes have been done: - libgmp10-6.1.2-4.9.1 updated . SUSE Container Maintenance Notification for suse/sle15, encompasses security enhancements and fixes for moderate vulnerabilities.. SUSE Container, Security Update, Buffer Overflow, Package Update. . LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:569-1 Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.58 Container Release : 9.5.58 Severity : moderate Type : security References : 1192717 CVE-2021-43618 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:3946-1 Released: Mon Dec 6 14:57:42 2021 Summary: Security update for gmp Type: security Severity: moderate References: 1192717,CVE-2021-43618 This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). The following package changes have been done: - libgmp10-6.1.2-4.9.1 updated . Essential security enhancement for suse/sle15 image resolving issue CVE-2021-43619, incorporating critical updates.. SUSE Container, gmp Update, SUSE Advisory, security patches. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gmp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3946-1 Rating: moderate References: #1192717 Cross-References: CVE-2021-43618 CVSS scores: CVE-2021-43618 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-43618 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3946=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 libgmpxx4-6.1.2-4.9.1 libgmpxx4-debuginfo-6.1.2-4.9.1 - openSUSE Leap 15.3 (x86_64): gmp-devel-32bit-6.1.2-4.9.1 libgmp10-32bit-6.1.2-4.9.1 libgmp10-32bit-debuginfo-6.1.2-4.9.1 libgmpxx4-32bit-6.1.2-4.9.1 libgmpxx4-32bit-debuginfo-6.1.2-4.9.1 References: https://www.suse.com/security/cve/CVE-2021-43618.html https://bugzilla.suse.com/1192717 . Patch released to address buffer overflow issue in GMP for openSUSE Leap 15.3. Discover steps to enhance your system security.. openSUSE Update, GMP Security Fix, Buffer Overflow Fix, Linux Advisory. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gmp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3946-1 Rating: moderate References: #1192717 Cross-References: CVE-2021-43618 CVSS scores: CVE-2021-43618 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-43618 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE MicroOS 5.1 SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gmp fixes the following issues: - CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2021-3946=1 - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-3946=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2021-3946=1 - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-3946=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-3946=1 - SUSE LinuxEnterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-3946=1 Package List: - SUSE MicroOS 5.1 (aarch64 s390x x86_64): gmp-debugsource-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 - SUSE MicroOS 5.0 (aarch64 x86_64): gmp-debugsource-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-32bit-6.1.2-4.9.1 libgmpxx4-32bit-6.1.2-4.9.1 libgmpxx4-32bit-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Development Tools 15-SP2 (x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-32bit-6.1.2-4.9.1 libgmpxx4-32bit-6.1.2-4.9.1 libgmpxx4-32bit-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 libgmpxx4-6.1.2-4.9.1 libgmpxx4-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (x86_64): libgmp10-32bit-6.1.2-4.9.1 libgmp10-32bit-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): gmp-debugsource-6.1.2-4.9.1 gmp-devel-6.1.2-4.9.1 libgmp10-6.1.2-4.9.1 libgmp10-debuginfo-6.1.2-4.9.1 libgmpxx4-6.1.2-4.9.1 libgmpxx4-debuginfo-6.1.2-4.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): libgmp10-32bit-6.1.2-4.9.1 libgmp10-32bit-debuginfo-6.1.2-4.9.1 References: https://www.suse.com/security/cve/CVE-2021-43618.html https://bugzilla.suse.com/1192717 . Ensure you download the newest SUSE security patch for gmp which fixes a moderate severity buffer overflow issue.. SUSE Security Update, gmp update, buffer overflow patch, SUSE MicroOS security, Security Fix. .LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.