CVE-2018-6485
published 2018-02-01CVE-2018-6485: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.69%
90.8th percentile
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.27-1 (bookworm) | glibc 2.27-1 (bookworm) |
| gnu | glibc | <= 2.26 | — |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.2 | 2.23-0ubuntu11.2 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.2 | 2.27-3ubuntu1.2 |
| netapp | storage_replication_adapter | >= 7.2 | — |
| netapp | vasa_provider | — | — |
| netapp | vasa_provider | >= 7.2 | — |
| netapp | virtual_storage_console | >= 7.2 | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_communications_broker | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operati
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2019-12-10
CVE-2018-6485 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: GNU C Library could be made to execute arbitrary code or cause a crash
if it received a specially crafted input.
Jakub Wilk discovered that GNU C Library incorrectly handled certain memory alignments.
An attacker could possibly use this issue to execute arbitrary code or cause
a crash.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2018-6485: glibc - An integer overflow in the implementation of the posix_memalign in memalign func...
vendor_debian·2018·CVSS 9.8
CVE-2018-6485 [CRITICAL] CVE-2018-6485: glibc - An integer overflow in the implementation of the posix_memalign in memalign func...
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
Scope: local
bookworm: resolved (fixed in 2.27-1)
bullseye: resolved (fixed in 2.27-1)
forky: resolved (fixed in 2.27-1)
sid: resolved (fixed in 2.27-1)
trixie: resolved (fixed in 2.27-1)
Red Hat
glibc: Integer overflow in posix_memalign in memalign functions
vendor_redhat·2017-10-10·CVSS 9.8
CVE-2018-6485 [CRITICAL] CWE-190 glibc: Integer overflow in posix_memalign in memalign functions
glibc: Integer overflow in posix_memalign in memalign functions
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
Statement: This issue affects the versions of glibc and compat-glibc as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: compat-glibc (Red Hat Enterpris
GHSA
GHSA-m775-r988-g6m4: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-13
CVE-2018-6485 [CRITICAL] CWE-787 GHSA-m775-r988-g6m4: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
OSV
glibc vulnerabilities
osv·2020-07-06·CVSS 5.9
CVE-2017-12133 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Florian Weimer discovered that the GNU C Library incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-12133)
It was discovered that the GNU C Library incorrectly handled certain
SSE2-optimized memmove operations. A remote attacker could use this issue
to cause the GNU C Library to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2017-18269)
It was discovered that the GNU C Library incorrectly handled certain
pathname operations. A remote attacker could use this issue to cause the
GNU C Library to cras
OSV
CVE-2018-6485: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2
osv·2018-02-01·CVSS 9.8
CVE-2018-6485 [CRITICAL] CVE-2018-6485: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions [fedora-all]
bugzilla·2018-02-05·CVSS 9.8
CVE-2018-6485 [CRITICAL] CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions [fedora-all]
CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions
bugzilla·2018-02-05·CVSS 9.8
CVE-2018-6485 [CRITICAL] CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions
CVE-2018-6485 glibc: Integer overflow in posix_memalign in memalign functions
A flaw was found in glibc. An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
References:
https://sourceware.org/bugzilla/show_bug.cgi?id=22343
Patch:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=8e448310d74b283c5cd02b9ed7fb997b47bf9b22
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1542103]
---
Statement:
This issue affects the versions of glibc and compat-glibc as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enter
http://bugs.debian.org/878159http://www.securityfocus.com/bid/102912https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3092https://security.netapp.com/advisory/ntap-20190404-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=22343https://usn.ubuntu.com/4218-1/https://usn.ubuntu.com/4416-1/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://bugs.debian.org/878159http://www.securityfocus.com/bid/102912https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3092https://security.netapp.com/advisory/ntap-20190404-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=22343https://usn.ubuntu.com/4218-1/https://usn.ubuntu.com/4416-1/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-02-01
Published