CVE-2023-39976
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-39976 affects libqb versions before 2.0.8, specifically in the log_blackbox.c component. The vulnerability was discovered and disclosed in August 2023. The affected software, libqb, is a library providing high-performance features for client-server architecture, including logging, tracing, inter-process communication, and polling (NVD).

Technical details

The vulnerability is a buffer overflow condition in log_blackbox.c that occurs when processing long log messages. The issue arises because the header size is not considered when calculating buffer space for log messages. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The buffer overflow vulnerability could potentially allow an attacker to execute arbitrary code, cause denial of service, or compromise system security through memory corruption. The high CVSS score indicates that successful exploitation could lead to complete system compromise with no special privileges or user interaction required (NVD).

Mitigation and workarounds

The vulnerability has been fixed in libqb version 2.0.8. The fix involves properly accounting for the header size when calculating the maximum length for formatted log messages. Users should upgrade to version 2.0.8 or later to address this security issue (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48639HIGH7.3
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management