CVE-2023-23456Active Exploitation(fedoraproject / fedora)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fedoraproject fedora systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • upx

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
fedoraupx

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-26: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-02-26: 102-26
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • David@davidsheyi
    Active Exploitation

    1/ Akira ransomware targets unpatched VPN servers, exploiting vulnerabilities like CVE-2023-23456. Ensure your systems are patched. #ThreatIntel #InfoSec

    Post summary

    Akira ransomware is actively exploiting CVE-2023-23456 on unpatched VPN servers, and the post urges users to patch their systems.

    1000099
    556 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora36--
OSfedoraprojectfedora37--
Appupxupx---

Explore more