Vulnerability Description
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious input file can cause undesirable behavior."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Llvm | Llvm | 2023-01-22 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Colloportus0/fc16d10d74aedf89d5d1d020ebb89c0cThird Party Advisory
- https://github.com/llvm/llvm-project/issues/60216ExploitIssue TrackingThird Party Advisory
- https://llvm.org/docs/Security.html#what-is-considered-a-security-issue
- https://gist.github.com/Colloportus0/fc16d10d74aedf89d5d1d020ebb89c0cThird Party Advisory
- https://github.com/llvm/llvm-project/issues/60216ExploitIssue TrackingThird Party Advisory
- https://llvm.org/docs/Security.html#what-is-considered-a-security-issue
FAQ
What is CVE-2023-26924?
CVE-2023-26924 is a vulnerability with a CVSS score of 5.5 (MEDIUM). LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for which a malicious inp...
How severe is CVE-2023-26924?
CVE-2023-26924 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26924?
Check the references section above for vendor advisories and patch information. Affected products include: Llvm Llvm.