{"id":"CVE-2023-32611","title":"A flaw was found in GLib","summary":"A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-400"],"vendor":"gnome","product":"glib","affected":["glib < 2.74.2"],"patched":["glib 2.74.2"],"published":"2023-09-14","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-32611","references":[{"url":"https://access.redhat.com/security/cve/CVE-2023-32611","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2211829","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/glib/-/issues/2797","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202311-18","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20231027-0005/","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-32611","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2211829","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gitlab.gnome.org/GNOME/glib/-/issues/2797","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202311-18","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20231027-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00379,"epssPercentile":0.31796,"ingestedAt":"2026-06-29T13:24:33.904Z","slug":"CVE-2023-32611","body":"## Overview\n\nA flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.\n\n## Affected\n\n- `glib < 2.74.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `glib 2.74.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}