An integer overflow was found in the __vsyslog_internal...
Moderate severity
Unreviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
•
Updated Feb 19, 2024
Description
Published by the National Vulnerability Database
Jan 31, 2024
Published to the GitHub Advisory Database
Jan 31, 2024
Last updated
Feb 19, 2024
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.
References