CVE-2023-4039 describes a disputed vulnerability in GCC-based toolchains targeting AArch64, where the -fstack-protector feature fails to detect buffer overflows in dynamically-sized local variables (C99-style or alloca()). This allows an attacker to exploit such overflows without triggering the stack-protector, potentially leading to uncontrolled loss of availability, or affecting confidentiality and integrity. The vulnerability has a CVSS score of 4.8 (MEDIUM), indicating a network attack vector with high attack complexity and low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, no public exploit code, and minimal community discussion, though it was mentioned on Reddit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-09-12CPE matchmatch criteria | cpe:2.3:a:gnu:gcc:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025CVE-2023-4039
Jul 9, 2024gcc: -fstack-protector fails to guard dynamic stack allocations on ARM64
Sep 12, 2023GCC's-fstack-protector fails to guard dynamically-sized local variables on AArch64
Sep 12, 2023