Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-6779

25
FAUCET Score

CVE-2023-6779 is an off-by-one heap-based buffer overflow in the glibc library's __vsyslog_internal function, affecting glibc versions 2.37 and newer, including Fedora distributions. This vulnerability, triggered by syslog or vsyslog calls with messages exceeding INT_MAX bytes, leads to an application crash due to incorrect buffer size calculation. Rated 7.5 HIGH, it presents a network-based, low-complexity attack vector with high availability impact. While no public exploit code or active exploitation is reported, it has garnered community attention and media coverage, indicating awareness of its potential.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE match
cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
>= 2.37, < 2.39CPE matchmatch criteria
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.15%
Probability of exploitation in next 30 days
EPSS Percentile
86.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0315 is in the 76th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.38-6
microsoftpatch availablevia msrc
Product: 19758-17084Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: 18299-17084Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-10 on Azure Linux 3.0Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-6 on Azure Linux 3.0Fixed in: 2.38-6

Vendor Advisories (3)

microsoft2024-Jun/CVE-2023-6779

CVE-2023-6779

Jun 11, 2024
redhatCVE-2023-6779Important

glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()

Jan 30, 2024
microsoft2024-Jan/CVE-2023-6779Important

Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()

Jan 9, 2024

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
packetstormsecurity.com / files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
access.redhat.com / security/cve/CVE-2023-6779
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
seclists.org / fulldisclosure/2024/Feb/3
ExploitMailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ
Mailing List
security.gentoo.org / glsa/202402-01
Third Party Advisory
security.netapp.com / advisory/ntap-20240223-0006
Third Party Advisory
openwall.com / lists/oss-security/2024/01/30/6
ExploitMailing List
qualys.com / 2024/01/30/cve-2023-6246/syslog.txt
Third Party Advisory