Ubuntu 22.04 LTS/23.04:LLVM 工具鏈弱點 (USN-6258-1)

medium Nessus Plugin ID 178947

概要

遠端 Ubuntu 主機缺少一個或多個安全性更新。

說明

遠端 Ubuntu 22.04 LTS / 23.04 主機上安裝的多個套件受到 USN-6258-1 公告中所提及的多個弱點影響。

- 發現 llvm-project commit fdbc55a5 包含分割錯誤,此錯誤是元件 mlir: : IROperand<mlir: : OpOperand 所導致。(CVE-2023-29932)

- 發現 llvm-project commit bd456297 包含分割錯誤,此錯誤是元件 mlir: : Block: : getArgument 所導致。(CVE-2023-29933)

- 發現 llvm-project commit 6c01b5c 包含分割錯誤,此錯誤是元件 mlir: : Type: : getDialect() 所導致。(CVE-2023-29934)

- 發現 llvm-project commit a0138390 包含分割錯誤,此錯誤是元件 mlir: : spirv: : TargetEnv: : TargetEnv(mlir: : spirv: : TargetEnvAttr) 所導致。(CVE-2023-29939)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

更新受影響的套件。

另請參閱

https://ubuntu.com/security/notices/USN-6258-1

Plugin 詳細資訊

嚴重性: Medium

ID: 178947

檔案名稱: ubuntu_USN-6258-1.nasl

版本: 1.0

類型: local

代理程式: unix

已發布: 2023/7/27

已更新: 2023/7/27

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

風險資訊

VPR

風險因素: Low

分數: 3.6

CVSS v2

風險因素: Medium

基本分數: 4.9

時間分數: 3.6

媒介: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2023-29939

CVSS v3

風險因素: Medium

基本分數: 5.5

時間分數: 4.8

媒介: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

CPE: cpe:/o:canonical:ubuntu_linux:22.04:-:lts, cpe:/o:canonical:ubuntu_linux:23.04, p-cpe:/a:canonical:ubuntu_linux:libclang-common-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-common-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp13-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15, p-cpe:/a:canonical:ubuntu_linux:libclang-cpp15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-14-dev-wasm64, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libclang-rt-15-dev-wasm64, p-cpe:/a:canonical:ubuntu_linux:libclang1-13, p-cpe:/a:canonical:ubuntu_linux:libclang1-14, p-cpe:/a:canonical:ubuntu_linux:libclang1-15, p-cpe:/a:canonical:ubuntu_linux:libclc-13, p-cpe:/a:canonical:ubuntu_linux:libclc-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-14, p-cpe:/a:canonical:ubuntu_linux:libclc-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclc-15, p-cpe:/a:canonical:ubuntu_linux:libclc-15-dev, p-cpe:/a:canonical:ubuntu_linux:libflang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-13-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-14-dev, p-cpe:/a:canonical:ubuntu_linux:libfuzzer-15-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-13, p-cpe:/a:canonical:ubuntu_linux:liblld-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-14, p-cpe:/a:canonical:ubuntu_linux:liblld-14-dev, p-cpe:/a:canonical:ubuntu_linux:bolt-15, p-cpe:/a:canonical:ubuntu_linux:clang-13, p-cpe:/a:canonical:ubuntu_linux:clang-13-examples, p-cpe:/a:canonical:ubuntu_linux:clang-14, p-cpe:/a:canonical:ubuntu_linux:clang-14-examples, p-cpe:/a:canonical:ubuntu_linux:clang-15, p-cpe:/a:canonical:ubuntu_linux:clang-15-examples, p-cpe:/a:canonical:ubuntu_linux:clang-format-13, p-cpe:/a:canonical:ubuntu_linux:clang-format-14, p-cpe:/a:canonical:ubuntu_linux:clang-format-15, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-13, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-14, p-cpe:/a:canonical:ubuntu_linux:clang-tidy-15, p-cpe:/a:canonical:ubuntu_linux:clang-tools-13, p-cpe:/a:canonical:ubuntu_linux:clang-tools-14, p-cpe:/a:canonical:ubuntu_linux:clang-tools-15, p-cpe:/a:canonical:ubuntu_linux:clangd-13, p-cpe:/a:canonical:ubuntu_linux:clangd-14, p-cpe:/a:canonical:ubuntu_linux:clangd-15, p-cpe:/a:canonical:ubuntu_linux:flang-15, p-cpe:/a:canonical:ubuntu_linux:libbolt-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-13-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-13, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2b1-15, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-13-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-14-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi-15-dev-wasm32, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-13, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-14, p-cpe:/a:canonical:ubuntu_linux:libc%2b%2babi1-15, p-cpe:/a:canonical:ubuntu_linux:libclang-13-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-14-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-15-dev, p-cpe:/a:canonical:ubuntu_linux:libclang-common-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblld-15, p-cpe:/a:canonical:ubuntu_linux:liblld-15-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-13, p-cpe:/a:canonical:ubuntu_linux:liblldb-13-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-14, p-cpe:/a:canonical:ubuntu_linux:liblldb-14-dev, p-cpe:/a:canonical:ubuntu_linux:liblldb-15, p-cpe:/a:canonical:ubuntu_linux:liblldb-15-dev, p-cpe:/a:canonical:ubuntu_linux:libllvm-13-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-tools, p-cpe:/a:canonical:ubuntu_linux:libllvm-14-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:libllvm-15-ocaml-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14, p-cpe:/a:canonical:ubuntu_linux:llvm-14-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-14-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-14-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-14-runtime, p-cpe:/a:canonical:ubuntu_linux:llvm-14-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-15, p-cpe:/a:canonical:ubuntu_linux:llvm-15-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-15-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-15-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-15-runtime, p-cpe:/a:canonical:ubuntu_linux:llvm-15-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-13-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-14-tools, p-cpe:/a:canonical:ubuntu_linux:mlir-15-tools, p-cpe:/a:canonical:ubuntu_linux:python3-clang-13, p-cpe:/a:canonical:ubuntu_linux:python3-clang-14, p-cpe:/a:canonical:ubuntu_linux:python3-clang-15, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-13, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-14, p-cpe:/a:canonical:ubuntu_linux:python3-lldb-15, p-cpe:/a:canonical:ubuntu_linux:libllvm13, p-cpe:/a:canonical:ubuntu_linux:libllvm14, p-cpe:/a:canonical:ubuntu_linux:libllvm15, p-cpe:/a:canonical:ubuntu_linux:libmlir-13, p-cpe:/a:canonical:ubuntu_linux:libmlir-13-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-14, p-cpe:/a:canonical:ubuntu_linux:libmlir-14-dev, p-cpe:/a:canonical:ubuntu_linux:libmlir-15, p-cpe:/a:canonical:ubuntu_linux:libmlir-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-13-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-14-dev, p-cpe:/a:canonical:ubuntu_linux:libomp-15-dev, p-cpe:/a:canonical:ubuntu_linux:libomp5-13, p-cpe:/a:canonical:ubuntu_linux:libomp5-14, p-cpe:/a:canonical:ubuntu_linux:libomp5-15, p-cpe:/a:canonical:ubuntu_linux:libpolly-14-dev, p-cpe:/a:canonical:ubuntu_linux:libpolly-15-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-13, p-cpe:/a:canonical:ubuntu_linux:libunwind-13-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-14, p-cpe:/a:canonical:ubuntu_linux:libunwind-14-dev, p-cpe:/a:canonical:ubuntu_linux:libunwind-15, p-cpe:/a:canonical:ubuntu_linux:libunwind-15-dev, p-cpe:/a:canonical:ubuntu_linux:lld-13, p-cpe:/a:canonical:ubuntu_linux:lld-14, p-cpe:/a:canonical:ubuntu_linux:lld-15, p-cpe:/a:canonical:ubuntu_linux:lldb-13, p-cpe:/a:canonical:ubuntu_linux:lldb-14, p-cpe:/a:canonical:ubuntu_linux:lldb-15, p-cpe:/a:canonical:ubuntu_linux:llvm-13, p-cpe:/a:canonical:ubuntu_linux:llvm-13-dev, p-cpe:/a:canonical:ubuntu_linux:llvm-13-examples, p-cpe:/a:canonical:ubuntu_linux:llvm-13-linker-tools, p-cpe:/a:canonical:ubuntu_linux:llvm-13-runtime

必要的 KB 項目: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2023/7/27

弱點發布日期: 2023/5/5

參考資訊

CVE: CVE-2023-29932, CVE-2023-29933, CVE-2023-29934, CVE-2023-29939

USN: 6258-1