CVE-2023-36328: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

Affected products

  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Libtom Libtommath: before 1.2.1 (fixed in 1.2.1)

Published 2023-09-01. Last modified 2026-06-17.