← Vulnerability feed

Vulnerability record · CVE-2023-0687 · published 6 February 2023

CVE-2023-0687: Gnu glibc classic buffer overflow vulnerability

Gnu · Glibc

A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.

9.8 CVSS 3.1 Critical EPSS 1.1% · top 35.9% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 4.0
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/ Patch
https://sourceware.org/bugzilla/show_bug.cgi?id=29444 Issue TrackingPatchThird Party Advisory
https://vuldb.com/?ctiid.220246 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.220246 Permissions RequiredThird Party Advisory
https://patchwork.sourceware.org/project/glibc/patch/20230204114138.5436-1-leo%40yuriev.ru/ Patch
https://sourceware.org/bugzilla/show_bug.cgi?id=29444 Issue TrackingPatchThird Party Advisory
https://vuldb.com/?ctiid.220246 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.220246 Permissions RequiredThird Party Advisory

Track CVE-2023-0687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed9.8CVE-2026-5450Gnu glibc heap-based buffer overflow vulnerabilityCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec…EPSS 0.72%9.8CVE-2023-25139Gnu glibc out-of-bounds write vulnerabilitysprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelate…EPSS 1.4%9.8CVE-2022-23218Gnu glibc classic buffer overflow vulnerabilityThe deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on t…EPSS 4.8%9.8CVE-2022-23219Gnu glibc classic buffer overflow vulnerabilityThe deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on …EPSS 4.3%9.8CVE-2021-33574Gnu glibc use after free vulnerabilityThe mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes ob…EPSS 2.9%9.8CVE-1999-0199Gnu glibc unchecked return value vulnerabilitymanual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2023-0687), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.