CVE-2019-19126 — Improper Initialization in Glibc
Severity
3.3LOWNVD
EPSS
0.0%
top 93.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateMay 24
Description
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4
Patches
🔴Vulnerability Details
3GHSA
▶
CVEList
▶
📋Vendor Advisories
4Microsoft▶
On the x86-64 architecture the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition allowing loc↗2019-11-12
Debian▶
CVE-2019-19126: glibc - On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to i...↗2019