CVE-2023-39976

Source
https://cve.org/CVERecord?id=CVE-2023-39976
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39976.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-39976
Downstream
AZL (2)
CLSA (1)
DEBIAN (1)
MGASA (1)
openSUSE (1)
RHSA (3)
SUSE (4)
UBUNTU (1)
Related
Published
2023-08-08T00:00:00Z
Modified
2026-08-12T14:51:02Z
Summary
[none]
Details

log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39976.json"
}
References

Affected packages

Git / github.com/clusterlabs/libqb

Affected ranges

Type
GIT
Repo
https://github.com/clusterlabs/libqb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:clusterlabs:libqb:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.0.8"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.9.0
libqb-0.*
libqb-0.0.0
libqb-0.1.0
v0.*
v0.1.0
v0.10.0
v0.10.1
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.14.4
v0.15.0
v0.16.0
v0.17.0
v0.17.0.rc1
v0.17.1
v0.17.1-rc1
v0.17.2
v0.2.0
v0.3.0
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.7.0
v0.8.0
v0.8.1
v0.9.0
v1.*
v1.0
v1.0.1
v1.0.2
v1.0.3
v1.0rc1
v1.0rc2
v1.0rc3
v1.0rc4
v1.9.0
v1.9.1
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39976.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "234310116874441598169012739281943531554",
                "88767074367043050548443721587077693599",
                "281001159218331700925163265004941775733",
                "263366324407121559883848862156710781083",
                "57683120494871408456411132952730974543"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2023-39976-c6b71c89",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/clusterlabs/libqb/commit/1bbaa929b77113532785c408dd1b41cd0521ffc8",
        "target":  {
            "file":  "lib/log_blackbox.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "144833620041746192361028286524335023369",
            "length":  1476
        },
        "id":  "CVE-2023-39976-e46cc8c4",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/clusterlabs/libqb/commit/1bbaa929b77113532785c408dd1b41cd0521ffc8",
        "target":  {
            "file":  "lib/log_blackbox.c",
            "function":  "_blackbox_vlogger"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "14394832875997190676591766158283567814",
            "length":  878
        },
        "id":  "CVE-2023-39976-e7ec4eb4",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/clusterlabs/libqb/commit/1bbaa929b77113532785c408dd1b41cd0521ffc8",
        "target":  {
            "file":  "tests/check_log.c",
            "function":  "START_TEST"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "220261002650673137112960086698603237908",
                "291825239214008548035429337321196903562",
                "181251568651179490113890241814114365331",
                "241978366710158549109347642762512271078",
                "38907448786194894788171967354211672238"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2023-39976-f763f945",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/clusterlabs/libqb/commit/1bbaa929b77113532785c408dd1b41cd0521ffc8",
        "target":  {
            "file":  "tests/check_log.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T14:51:02Z"