CVE-2018-6551
published 2018-02-02CVE-2018-6551: The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly…
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.19%
80.5th percentile
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.27-1 (bookworm) | glibc 2.27-1 (bookworm) |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | >= 0 < 2.27-1 | 2.27-1 |
| gnu | glibc | 2.24 – 2.26 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-39wv-6252-46w2: The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2
ghsa_unreviewed·2022-05-13
CVE-2018-6551 [CRITICAL] CWE-787 GHSA-39wv-6252-46w2: The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
OSV
CVE-2018-6551: The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2
osv·2018-02-02·CVSS 9.8
CVE-2018-6551 [CRITICAL] CVE-2018-6551: The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
Red Hat
glibc: integer overflow in malloc functions
vendor_redhat·2018-02-02·CVSS 9.8
CVE-2018-6551 [CRITICAL] CWE-190 glibc: integer overflow in malloc functions
glibc: integer overflow in malloc functions
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
Statement: This issue did not affect the versions of glibc and compat-glibc as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Not affected
Package: glibc (Red Hat Enterprise Linux 5) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Package: compat-glibc (Red Hat Enterprise L
Debian
CVE-2018-6551: glibc - The malloc implementation in the GNU C Library (aka glibc or libc6), from versio...
vendor_debian·2018·CVSS 9.8
CVE-2018-6551 [CRITICAL] CVE-2018-6551: glibc - The malloc implementation in the GNU C Library (aka glibc or libc6), from versio...
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
Scope: local
bookworm: resolved (fixed in 2.27-1)
bullseye: resolved (fixed in 2.27-1)
forky: resolved (fixed in 2.27-1)
sid: resolved (fixed in 2.27-1)
trixie: resolved (fixed in 2.27-1)
No detection rules found.
No public exploits indexed.
https://security.netapp.com/advisory/ntap-20190404-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=22774https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=8e448310d74b283c5cd02b9ed7fb997b47bf9b22https://security.netapp.com/advisory/ntap-20190404-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=22774https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=8e448310d74b283c5cd02b9ed7fb997b47bf9b22
2018-02-02
Published