CVE-2023-26924

NameCVE-2023-26924
DescriptionLLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
llvm-toolchain-14 (PTS)bookworm1:14.0.6-12vulnerable
trixie1:14.0.6-16vulnerable
sid1:14.0.6-17vulnerable
llvm-toolchain-15 (PTS)bookworm1:15.0.6-4vulnerable
trixie1:15.0.7-10vulnerable
sid1:15.0.7-12vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
llvm-toolchain-14source(unstable)(unfixed)unimportant
llvm-toolchain-15source(unstable)(unfixed)unimportant

Notes

Negligible security impact, also see https://llvm.org/docs/Security.html#what-is-considered-a-security-issue

Search for package or bug name: Reporting problems