---
title: "CVE-2023-2976\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-2976?format=md
keywords: index, follow
---

# CVE-2023-2976

Publication date 14 June 2023

Last updated 19 January 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2023-2976?format=md#impact-score)

Toggle side navigation

## Description

Use of Java's default temporary directory for file creation in
`FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix
systems and Android Ice Cream Sandwich allows other users and apps on the
machine with access to the default Java temporary directory to be able to
access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we
recommend using version 32.0.1 as version 32.0.0 breaks some functionality
under Windows.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| guava-libraries | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2023-2976?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| guava-libraries | * Upstream:   [feb83a1](https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2976)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-2976)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-2976)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-2976)

### Other references

* <https://github.com/google/guava/releases/tag/v32.0.0>
* <https://github.com/google/guava/issues/2575>
* <https://www.cve.org/CVERecord?id=CVE-2023-2976>
