Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
libeconf could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8368-1 June 02, 2026 libeconf vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: libeconf could be made to crash if it received specially crafted input. Software Description: - libeconf: highly flexible and configurable library to parse and manage key=value configuration files Details: It was discovered that libeconf did not properly check the size of input when copying data to a buffer. An attacker could possibly use this issue to cause libeconf to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libeconf0 0.3.8-1+deb11u1build0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8368-1 CVE-2023-22652 Package Information: https://launchpad.net/ubuntu/+source/libeconf/0.3.8-1+deb11u1build0.22.04.1 . A critical vulnerability in libeconf may cause denial of service on Ubuntu 22.04 with specially crafted input.. Ubuntu security, libeconf update, denial of service, buffer overflow. . Severity: Critical. LinuxSecurity.com Team
libeconf could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8368-1 June 02, 2026 libeconf vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: libeconf could be made to crash if it received specially crafted input. Software Description: - libeconf: highly flexible and configurable library to parse and manage key=value configuration files Details: It was discovered that libeconf did not properly check the size of input when copying data to a buffer. An attacker could possibly use this issue to cause libeconf to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libeconf0 0.3.8-1+deb11u1build0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8368-1 CVE-2023-22652 Package Information: https://launchpad.net/ubuntu/+source/libeconf/0.3.8-1+deb11u1build0.22.04.1 . ubuntu advisory for libeconf handling specially crafted input leading to DoS vulnerability and suggested updates.. libeconf security patch, ubuntu 22.04 security advisory, DoS vulnerability fix, update instructions, input handling crash. . Severity: Low. LinuxSecurity.com Team
It was discovered that there was a potential buffer overflow vulnerability in libeconf, a configuration file parser. This could have been exploited via malicously-crafted configuration files. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4164-1
* bsc#1211078 Cross-References: * CVE-2023-22652 * CVE-2023-30078 . # Security update for libeconf Announcement ID: SUSE-SU-2024:2426-1 Rating: important References: * bsc#1211078 Cross-References: * CVE-2023-22652 * CVE-2023-30078 * CVE-2023-30079 * CVE-2023-32181 CVSS scores: * CVE-2023-22652 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-22652 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-30078 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-30078 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-30079 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-30079 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-32181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-32181 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libeconf fixes the following issues: Update to version 0.5.2. * CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in "econf_writeFile" function (bsc#1211078). * CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in "read_file" function. (bsc#1211078) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-2426=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (ppc64le) * libeconf0-debuginfo-0.5.2-150400.3.6.1 * libeconf0-0.5.2-150400.3.6.1 * libeconf-debugsource-0.5.2-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-22652.html * https://www.suse.com/security/cve/CVE-2023-30078.html *https://www.suse.com/security/cve/CVE-2023-30079.html * https://www.suse.com/security/cve/CVE-2023-32181.html * https://bugzilla.suse.com/show_bug.cgi?id=1211078 . Important announcement regarding SUSE Linux that tackles various security vulnerabilities in libeconf. Apply the necessary patch to ensure your system's safety.. SUSE Linux, libeconf, security patch, software update, stack overflow. . Severity: Important. LinuxSecurity.com Team
Moderate: libeconf security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4347", "synopsis": "Moderate: libeconf security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libeconf.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Libeconf is a highly flexible and configurable library to parse and manage key=value configuration files. It reads configuration file snippets from different directories and builds the final configuration file from it.\n\nSecurity Fix(es):\n\n* libeconf: stack-based buffer overflow in read_file() in lib/getfilecontents.c (CVE-2023-22652)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2212463", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2212463", "description": ""}], "cves": [{"name": "CVE-2023-22652", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-22652", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-120"}, {"name": "CVE-2023-30079", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-30079", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-121"}], "references": [], "publishedAt": "2023-10-06T23:10:28.251866Z", "rpms": {"Rocky Linux 9": {"nvras": ["libeconf-0:0.4.1-3.el9_2.aarch64.rpm", "libeconf-0:0.4.1-3.el9_2.i686.rpm", "libeconf-0:0.4.1-3.el9_2.ppc64le.rpm", "libeconf-0:0.4.1-3.el9_2.s390x.rpm", "libeconf-0:0.4.1-3.el9_2.src.rpm", "libeconf-0:0.4.1-3.el9_2.x86_64.rpm", "libeconf-debuginfo-0:0.4.1-3.el9_2.aarch64.rpm","libeconf-debuginfo-0:0.4.1-3.el9_2.ppc64le.rpm", "libeconf-debuginfo-0:0.4.1-3.el9_2.s390x.rpm", "libeconf-debuginfo-0:0.4.1-3.el9_2.x86_64.rpm", "libeconf-debugsource-0:0.4.1-3.el9_2.aarch64.rpm", "libeconf-debugsource-0:0.4.1-3.el9_2.ppc64le.rpm", "libeconf-debugsource-0:0.4.1-3.el9_2.s390x.rpm", "libeconf-debugsource-0:0.4.1-3.el9_2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The recent security patch for Rocky Linux 9 resolves a moderate risk stack-based buffer overflow vulnerability in Libconf.. Rocky Linux Security Update,Libeconf Buffer Overflow,RLSA-2023:4347,Security Advisory. . LinuxSecurity.com Team
The container bci/openjdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3292-1 Container Tags : bci/openjdk:11 , bci/openjdk:11-11.6 Container Release : 11.6 Severity : important Type : security References : 1211078 1215683 1215684 1215685 CVE-2023-22652 CVE-2023-30078 CVE-2023-30079 CVE-2023-32181 CVE-2023-43785 CVE-2023-43786 CVE-2023-43787 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3954-1 Released: Tue Oct 3 20:09:47 2023 Summary: Security update for libeconf Type: security Severity: important References: 1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 This update for libeconf fixes the following issues: Update to version 0.5.2. - CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078). - CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3963-1 Released: Wed Oct 4 09:24:32 2023 Summary: Security update for libX11 Type: security Severity: moderate References: 1215683,1215684,1215685,CVE-2023-43785,CVE-2023-43786,CVE-2023-43787 This update for libX11 fixes the following issues: - CVE-2023-43786: Fixed stack exhaustion from infinite recursion in PutSubImage() (bsc#1215684). - CVE-2023-43787: Fixed integer overflow in XCreateImage() leading to a heap overflow (bsc#1215685). - CVE-2023-43785: Fixed out-of-bounds memory access in _XkbReadKeySyms() (bsc#1215683). The followingpackage changes have been done: - libeconf0-0.5.2-150400.3.6.1 updated - libX11-data-1.6.5-150000.3.33.1 updated - libX11-6-1.6.5-150000.3.33.1 updated - container:sles15-image-15.0.0-36.5.39 updated . Significant revisions have been released for bci/openjdk and associated elements, delineating security functionalities from potential threats.. container security, bci/openjdk, libeconf security, libX11 updates, important security advisory. . Severity: Important. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3278-1 Container Tags : bci/python:3 , bci/python:3-15.61 , bci/python:3.10 , bci/python:3.10-15.61 Container Release : 15.61 Severity : important Type : security References : 1211078 CVE-2023-22652 CVE-2023-30078 CVE-2023-30079 CVE-2023-32181 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3954-1 Released: Tue Oct 3 20:09:47 2023 Summary: Security update for libeconf Type: security Severity: important References: 1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 This update for libeconf fixes the following issues: Update to version 0.5.2. - CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078). - CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078) The following package changes have been done: - libeconf0-0.5.2-150400.3.6.1 updated - container:sles15-image-15.0.0-27.14.103 updated . SUSE Container Advisory released for key bci/python updates and significant libeconf security corrections. Keep your systems secure!. SUSE Container Advisory, bci/python Update, Security Fixes. . Severity: Important. LinuxSecurity.com Team
The container suse/postgres was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3277-1 Container Tags : suse/postgres:14 , suse/postgres:14-22.71 , suse/postgres:14.9 , suse/postgres:14.9-22.71 Container Release : 22.71 Severity : important Type : security References : 1211078 CVE-2023-22652 CVE-2023-30078 CVE-2023-30079 CVE-2023-32181 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3954-1 Released: Tue Oct 3 20:09:47 2023 Summary: Security update for libeconf Type: security Severity: important References: 1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 This update for libeconf fixes the following issues: Update to version 0.5.2. - CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078). - CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078) The following package changes have been done: - libeconf0-0.5.2-150400.3.6.1 updated - container:sles15-image-15.0.0-27.14.103 updated . Critical updates for SUSE: PostgreSQL addresses significant resolutions for buffer overflow risks within libeconf.. SUSE Container Security Update, Postgres Update, Libeconf Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.