logo

Qualys TRU Discovers Important Vulnerabilities in GNU C Library’s syslog()

ID: 937abe8d-d006-51b9-9673-e896f18b27ea

STIX ID: report--937abe8d-d006-51b9-9673-e896f18b27ea

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2024-01-30

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Qualys Threat Research Unit disclosed multiple serious vulnerabilities in the GNU C Library, most notably a heap-based buffer overflow in __vsyslog_internal (CVE-2023-6246) allowing local privilege escalation to root on many Linux distributions, two additional lesser syslog issues (CVE-2023-6779, CVE-2023-6780), and a qsort() memory corruption due to a missing bounds check; patches and coordinated disclosure details are provided along with Qualys detection and QID coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.