Bug 1208696 (CVE-2023-26257) - VUL-0: CVE-2023-26257: dlt-daemon: Dynamic memory not released after it is allocated in dlt-control-common.c
Summary: VUL-0: CVE-2023-26257: dlt-daemon: Dynamic memory not released after it is al...
Status: IN_PROGRESS
Alias: CVE-2023-26257
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.4
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Pavel Zhukov
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/358354/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-02-27 12:27 UTC by Thomas Leroy
Modified: 2023-03-14 09:26 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-02-27 12:27:00 UTC
CVE-2023-26257

An issue was discovered in the Connected Vehicle Systems Alliance (COVESA;
formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after
it is allocated in dlt-control-common.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26257
https://bugzilla.redhat.com/show_bug.cgi?id=2173585
https://www.cve.org/CVERecord?id=CVE-2023-26257
https://github.com/COVESA/dlt-daemon/issues/440
https://github.com/COVESA/dlt-daemon/pull/441/commits/b6149e203f919c899fefc702a17fbb78bdec3700
Comment 1 Thomas Leroy 2023-02-27 12:28:21 UTC
Affected:
- openSUSE:Factory