CVE-2023-23457: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
Affected products
- Fedoraproject Fedora: version 36 only; version 37 only
- Upx Upx: before 2022-11-23 (fixed in 2022-11-23)
Published 2023-01-12. Last modified 2026-06-17.