CVE-2019-6488

CWE-404CWE-84310 documents8 sources
Severity
7.8HIGH
EPSS
0.1%
top 64.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 18
Latest updateMay 13

Description

The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in __memmove_avx_unaligned_erms in sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S during a memcpy.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianglibc< 2.28-6+3
NVDgnu/glibc2.28

🔴Vulnerability Details

3
GHSA
GHSA-7x9c-h7v7-85mv: The string component in the GNU C Library (aka glibc or libc6) through 22022-05-13
OSV
CVE-2019-6488: The string component in the GNU C Library (aka glibc or libc6) through 22019-01-18
CVEList
CVE-2019-6488: The string component in the GNU C Library (aka glibc or libc6) through 22019-01-18

📋Vendor Advisories

3
Red Hat
glibc: Incorrect attempt to use a 64-bit register for size_t in assembly codes results in segmentation fault2019-01-16
Microsoft
The string component in the GNU C Library (aka glibc or libc6) through 2.28 when running on the x32 architecture incorrectly attempts to use a 64-bit register for size_t in assembly codes which can le2019-01-08
Debian
CVE-2019-6488: glibc - The string component in the GNU C Library (aka glibc or libc6) through 2.28, whe...2019

💬Community

3
Bugzilla
CVE-2019-6488 glibc: Incorrect attempt to use a 64-bit register for size_t in assembly codes results in segmentation fault [fedora-all]2019-01-21
Bugzilla
CVE-2019-6488 glibc: Incorrect attempt to use a 64-bit register for size_t in assembly codes results in segmentation fault2019-01-21
Bugzilla
CVE-2019-0548 Asp.NET Core: AspNetCoreModule WebSocket DOS2018-12-18
CVE-2019-6488 (HIGH CVSS 7.8) | The string component in the GNU C L | cvebase.io