vulnerability

Red Hat: CVE-2023-25193: allows attackers to trigger O(n^2) growth via consecutive marks (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2023-02-04
Added
2023-07-21
Modified
2025-03-17

Description

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Solution(s)

redhat-upgrade-harfbuzzredhat-upgrade-harfbuzz-debuginforedhat-upgrade-harfbuzz-debugsourceredhat-upgrade-harfbuzz-develredhat-upgrade-harfbuzz-devel-debuginforedhat-upgrade-harfbuzz-icuredhat-upgrade-harfbuzz-icu-debuginforedhat-upgrade-java-11-openjdkredhat-upgrade-java-11-openjdk-debuginforedhat-upgrade-java-11-openjdk-debugsourceredhat-upgrade-java-11-openjdk-demoredhat-upgrade-java-11-openjdk-demo-fastdebugredhat-upgrade-java-11-openjdk-demo-slowdebugredhat-upgrade-java-11-openjdk-develredhat-upgrade-java-11-openjdk-devel-debuginforedhat-upgrade-java-11-openjdk-devel-fastdebugredhat-upgrade-java-11-openjdk-devel-fastdebug-debuginforedhat-upgrade-java-11-openjdk-devel-slowdebugredhat-upgrade-java-11-openjdk-devel-slowdebug-debuginforedhat-upgrade-java-11-openjdk-fastdebugredhat-upgrade-java-11-openjdk-fastdebug-debuginforedhat-upgrade-java-11-openjdk-headlessredhat-upgrade-java-11-openjdk-headless-debuginforedhat-upgrade-java-11-openjdk-headless-fastdebugredhat-upgrade-java-11-openjdk-headless-fastdebug-debuginforedhat-upgrade-java-11-openjdk-headless-slowdebugredhat-upgrade-java-11-openjdk-headless-slowdebug-debuginforedhat-upgrade-java-11-openjdk-javadocredhat-upgrade-java-11-openjdk-javadoc-zipredhat-upgrade-java-11-openjdk-jmodsredhat-upgrade-java-11-openjdk-jmods-fastdebugredhat-upgrade-java-11-openjdk-jmods-slowdebugredhat-upgrade-java-11-openjdk-slowdebugredhat-upgrade-java-11-openjdk-slowdebug-debuginforedhat-upgrade-java-11-openjdk-srcredhat-upgrade-java-11-openjdk-src-fastdebugredhat-upgrade-java-11-openjdk-src-slowdebugredhat-upgrade-java-11-openjdk-static-libsredhat-upgrade-java-11-openjdk-static-libs-fastdebugredhat-upgrade-java-11-openjdk-static-libs-slowdebugredhat-upgrade-java-17-openjdkredhat-upgrade-java-17-openjdk-debuginforedhat-upgrade-java-17-openjdk-debugsourceredhat-upgrade-java-17-openjdk-demoredhat-upgrade-java-17-openjdk-demo-fastdebugredhat-upgrade-java-17-openjdk-demo-slowdebugredhat-upgrade-java-17-openjdk-develredhat-upgrade-java-17-openjdk-devel-debuginforedhat-upgrade-java-17-openjdk-devel-fastdebugredhat-upgrade-java-17-openjdk-devel-fastdebug-debuginforedhat-upgrade-java-17-openjdk-devel-slowdebugredhat-upgrade-java-17-openjdk-devel-slowdebug-debuginforedhat-upgrade-java-17-openjdk-fastdebugredhat-upgrade-java-17-openjdk-fastdebug-debuginforedhat-upgrade-java-17-openjdk-headlessredhat-upgrade-java-17-openjdk-headless-debuginforedhat-upgrade-java-17-openjdk-headless-fastdebugredhat-upgrade-java-17-openjdk-headless-fastdebug-debuginforedhat-upgrade-java-17-openjdk-headless-slowdebugredhat-upgrade-java-17-openjdk-headless-slowdebug-debuginforedhat-upgrade-java-17-openjdk-javadocredhat-upgrade-java-17-openjdk-javadoc-zipredhat-upgrade-java-17-openjdk-jmodsredhat-upgrade-java-17-openjdk-jmods-fastdebugredhat-upgrade-java-17-openjdk-jmods-slowdebugredhat-upgrade-java-17-openjdk-slowdebugredhat-upgrade-java-17-openjdk-slowdebug-debuginforedhat-upgrade-java-17-openjdk-srcredhat-upgrade-java-17-openjdk-src-fastdebugredhat-upgrade-java-17-openjdk-src-slowdebugredhat-upgrade-java-17-openjdk-static-libsredhat-upgrade-java-17-openjdk-static-libs-fastdebugredhat-upgrade-java-17-openjdk-static-libs-slowdebug
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.