cbcvebase.
CVE-2019-7309
published 2019-02-03

CVE-2019-7309: In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs…

PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.61%
45.5th percentile
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.28-6 (bookworm)glibc 2.28-6 (bookworm)
gnuglibc<= 2.29
gnuglibc>= 0 < 2.28-62.28-6
gnuglibc>= 0 < 2.28-62.28-6
gnuglibc>= 0 < 2.28-62.28-6
gnuglibc>= 0 < 2.28-62.28-6
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_glibc_2.28-14_on_cbl_mariner_1.0

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.