Segmentation Fault in LLVM's mlir::outlineSingleBlockRegion Affects Multiple Languages
CVE-2023-26924

5.5MEDIUM

Key Information:

Vendor

Llvm

Status
Vendor
CVE Published:
27 March 2023

What is CVE-2023-26924?

A segmentation fault has been identified in LLVM's mlir::outlineSingleBlockRegion, which can lead to unexpected behavior when processing certain inputs. This issue has raised concerns as third parties argue it falls outside LLVM's security policy, which excludes vulnerabilities linked to language front-ends that process potentially malicious input files.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.