|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-35325: petsc: libyaml: double-free in yaml_event_delete in /src/libyaml/src/api.c | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | Camila Camargo de Matos <camila.matos> |
| Component: | Security | Assignee: | Egbert Eich <eich> |
| Status: | RESOLVED INVALID | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | camila.matos, security-team, smash_bz |
| Version: | Leap 15.6 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/410664/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1226342 | ||
|
Description
Camila Camargo de Matos
2024-06-14 14:24:01 UTC
Although petsc embeds a copy of libyaml (since version 3.15), the upstream README file present in the directory where the libyaml code can be found [0] states that this copy is partial, and does not include the "emitter API and other output-related parts". openSUSE:Factory/petsc does not seem to include any of the functions listed in the POC step-by-step [1], meaning this bug will be closed as petsc seems to not be affected by the vulnerability considered here. [0] https://gitlab.com/petsc/petsc/-/blob/main/src/sys/yaml/README.md?ref_type=heads [1] https://github.com/idhyt/pocs/blob/main/libyaml/CVE-2024-35325.c |