Ubuntu 22.04 LTS / 23.04 : LLVM Toolchain vulnerabilities (USN-6258-1)

medium Nessus Plugin ID 178947

Synopsis

The remote Ubuntu host is missing one or more security updates.

Description

The remote Ubuntu 22.04 LTS / 23.04 host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-6258-1 advisory.

- llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand. (CVE-2023-29932)

- llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument. (CVE-2023-29933)

- llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect(). (CVE-2023-29934)

- llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr). (CVE-2023-29939)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://ubuntu.com/security/notices/USN-6258-1

Plugin Details

Severity: Medium

ID: 178947

File Name: ubuntu_USN-6258-1.nasl

Version: 1.0

Type: local

Agent: unix

Published: 7/27/2023

Updated: 7/27/2023

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-29939

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:canonical:ubuntu_linux:22.04:-:lts, cpe:/o:canonical:ubuntu_linux:23.04, p-cpe:/a:canonical:ubuntu_linux:libclang-common-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-common-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm64, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm64, p-cpe:/a:canonical:ubuntu_linux:libclang1-13, p-cpe:/a:canonical:ubuntu_linux:libclang1-14, p-cpe:/a:canonical:ubuntu_linux:libclang1-15, p-cpe:/a:canonical:ubuntu_linux:libclc-13, p-cpe:/a:canonical:ubuntu_linux:libclc-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-14, p-cpe:/a:canonical:ubuntu_linux:libclc-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-15, p-cpe:/a:canonical:ubuntu_linux:libclc-15-dev, p-cpe:/a:canonical:ubuntu_linux:libflang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-13-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-14-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-15-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-13, p-cpe:/a:canonical:ubuntu_linux:liblld-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-14, p-cpe:/a:canonical:ubuntu_linux:liblld-14-dev, p-cpe:/a:canonical:ubuntu_linux:bolt-15, p-cpe:/a:canonical:ubuntu_linux:clang-13, p-cpe:/a:canonical:ubuntu_linux:clang-13-examples, p-cpe:/a:canonical:ubuntu_linux:clang-14, p-cpe:/a:canonical:ubuntu_linux:clang-14-examples, p-cpe:/a:canonical:ubuntu_linux:clang-15, p-cpe:/a:canonical:ubuntu_linux:clang-15-examples, p-cpe:/a:canonical:ubuntu_linux:clang-format-13, p-cpe:/a:canonical:ubuntu_linux:clang-format-14, p-cpe:/a:canonical:ubuntu_linux:clang-format-15, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-13, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-14, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-15, p-cpe:/a:canonical:ubuntu_linux:clang-tools-13, p-cpe:/a:canonical:ubuntu_linux:clang-tools-14, p-cpe:/a:canonical:ubuntu_linux:clang-tools-15, p-cpe:/a:canonical:ubuntu_linux:clangd-13, p-cpe:/a:canonical:ubuntu_linux:clangd-14, p-cpe:/a:canonical:ubuntu_linux:clangd-15, p-cpe:/a:canonical:ubuntu_linux:flang-15, p-cpe:/a:canonical:ubuntu_linux:libbolt-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-13-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-13, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-13-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-13, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-15, p-cpe:/a:canonical:ubuntu_linux:libclang-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-common-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-15, p-cpe:/a:canonical:ubuntu_linux:liblld-15-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-13, p-cpe:/a:canonical:ubuntu_linux:liblldb-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-14, p-cpe:/a:canonical:ubuntu_linux:liblldb-14-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-15, p-cpe:/a:canonical:ubuntu_linux:liblldb-15-dev, p-cpe:/a:canonical:ubuntu_linux:libllvm-13-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-tools, p-cpe:/a:canonical:ubuntu_linux:libllvm-14-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:libllvm-15-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14, p-cpe:/a:canonical:ubuntu_linux:llvm-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-14-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-14-runtime, p-cpe:/a:canonical:ubuntu_linux:llvm-14-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-15, p-cpe:/a:canonical:ubuntu_linux:llvm-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-15-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-15-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-15-runtime, p-cpe:/a:canonical:ubuntu_linux:llvm-15-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-13-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-14-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-15-tools, p-cpe:/a:canonical:ubuntu_linux:python3-clang-13, p-cpe:/a:canonical:ubuntu_linux:python3-clang-14, p-cpe:/a:canonical:ubuntu_linux:python3-clang-15, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-13, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-14, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-15, p-cpe:/a:canonical:ubuntu_linux:libllvm13, p-cpe:/a:canonical:ubuntu_linux:libllvm14, p-cpe:/a:canonical:ubuntu_linux:libllvm15, p-cpe:/a:canonical:ubuntu_linux:libmlir-13, p-cpe:/a:canonical:ubuntu_linux:libmlir-13-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-14, p-cpe:/a:canonical:ubuntu_linux:libmlir-14-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-15, p-cpe:/a:canonical:ubuntu_linux:libmlir-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-13-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-14-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp5-13, p-cpe:/a:canonical:ubuntu_linux:libomp5-14, p-cpe:/a:canonical:ubuntu_linux:libomp5-15, p-cpe:/a:canonical:ubuntu_linux:libpolly-14-dev, p-cpe:/a:canonical:ubuntu_linux:libpolly-15-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-13, p-cpe:/a:canonical:ubuntu_linux:libunwind-13-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-14, p-cpe:/a:canonical:ubuntu_linux:libunwind-14-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-15, p-cpe:/a:canonical:ubuntu_linux:libunwind-15-dev, p-cpe:/a:canonical:ubuntu_linux:lld-13, p-cpe:/a:canonical:ubuntu_linux:lld-14, p-cpe:/a:canonical:ubuntu_linux:lld-15, p-cpe:/a:canonical:ubuntu_linux:lldb-13, p-cpe:/a:canonical:ubuntu_linux:lldb-14, p-cpe:/a:canonical:ubuntu_linux:lldb-15, p-cpe:/a:canonical:ubuntu_linux:llvm-13, p-cpe:/a:canonical:ubuntu_linux:llvm-13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-13-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-13-runtime

Required KB Items: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release

Exploit Ease: No known exploits are available

Patch Publication Date: 7/27/2023

Vulnerability Publication Date: 5/5/2023

Reference Information

CVE: CVE-2023-29932, CVE-2023-29933, CVE-2023-29934, CVE-2023-29939

USN: 6258-1