USN-6620-1: GNU C Library vulnerabilities
1 February 2024
GNU C Library could be made to crash or run programs as an administrator if it handled a specially crafted request.
Releases
Packages
- glibc - GNU C Library
Details
It was discovered that the GNU C Library incorrectly handled the syslog()
function call. A local attacker could use this issue to execute arbitrary
code and possibly escalate privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.10
After a standard system update you need to reboot your computer to make all
the necessary changes.