CVE-2017-18269
Summary
| CVE | CVE-2017-18269 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-18 16:29:00 UTC |
| Updated | 2023-11-07 02:41:00 UTC |
| Description | An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Glibc | All | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 22644 – (CVE-2017-18269) memmove-sse2-unaligned on 32bit x86 produces garbage when crossing 2GB threshold (CVE-2017-18269) | MISC | sourceware.org | Issue Tracking |
| GitHub - fingolfin/memmove-bug: Reproducing a bug in GNU libc's memmove | MISC | github.com | Third Party Advisory |
| sourceware.org Git - glibc.git/commit | MISC | sourceware.org | Patch |
| May 2018 GNU C Library Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| NetApp Product Security | CONFIRM | security.netapp.com | |
| sourceware.org Git - glibc.git/commit | sourceware.org | ||
| USN-4416-1: GNU C Library vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.