CVE-2023-22483

NameCVE-2023-22483
Descriptioncmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. Various commands, when piped to cmark-gfm with large values, cause the running time to increase quadratically. These vulnerabilities have been patched in version 0.29.0.gfm.7.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1033110, 1033111, 1033112, 1033113

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cmark-gfm (PTS)bullseye0.29.0.gfm.0-6vulnerable
bookworm0.29.0.gfm.6-6vulnerable
trixie0.29.0.gfm.13-4fixed
forky, sid0.29.0.gfm.13-7fixed
python-cmarkgfm (PTS)bullseye0.4.2-1vulnerable
bookworm0.8.0-3vulnerable
forky, sid, trixie2024.11.20-1fixed
r-cran-commonmark (PTS)bullseye1.7-2vulnerable
bookworm1.8.1-1vulnerable
forky, sid, trixie1.9.5-1fixed
ruby-commonmarker (PTS)bullseye0.21.0-1vulnerable
bookworm0.23.6-1vulnerable
forky, sid, trixie0.23.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cmark-gfmsource(unstable)0.29.0.gfm.13-11033110
python-cmarkgfmsource(unstable)2024.11.20-11033111
r-cran-commonmarksource(unstable)1.9.0-11033112
ruby-commonmarkersource(unstable)0.23.10-11033113

Notes

[bookworm] - cmark-gfm <no-dsa> (Minor issue)
[bullseye] - cmark-gfm <no-dsa> (Minor issue)
[buster] - cmark-gfm <no-dsa> (Minor issue)
[bookworm] - python-cmarkgfm <no-dsa> (Minor issue)
[bullseye] - python-cmarkgfm <no-dsa> (Minor issue)
[buster] - python-cmarkgfm <no-dsa> (Minor issue)
[bookworm] - r-cran-commonmark <ignored> (Minor issue)
[bullseye] - r-cran-commonmark <no-dsa> (Minor issue)
[buster] - r-cran-commonmark <no-dsa> (Minor issue)
[bookworm] - ruby-commonmarker <ignored> (Minor issue)
[bullseye] - ruby-commonmarker <no-dsa> (Minor issue)
[buster] - ruby-commonmarker <no-dsa> (Minor issue)
https://github.com/github/cmark-gfm/security/advisories/GHSA-29g3-96g3-jg6c
https://github.com/theacodes/cmarkgfm/commit/acf473a51a9dc3a4fd6d6a4b30e4d80c94d91d4a (2024.1.14)
r-cran-commonmark: https://github.com/r-lib/commonmark/commit/e7a1703cf293eaa898e6f0cf07d278cfb05590eb (v1.9.0)

Search for package or bug name: Reporting problems