CVE-2019-6488
Summary
| CVE | CVE-2019-6488 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-18 19:29:00 UTC |
| Updated | 2020-06-13 03:15:00 UTC |
| Description | The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in __memmove_avx_unaligned_erms in sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S during a memcpy. |
Risk And Classification
Problem Types: CWE-404
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 24097 – (CVE-2019-6488) Can't use 64-bit register for size_t in assembly codes for x32 (CVE-2019-6488) | MISC | sourceware.org | Issue Tracking, Third Party Advisory |
| glibc: Multiple vulnerabilities (GLSA 202006-04) — Gentoo security | GENTOO | security.gentoo.org | |
| GNU glibc CVE-2019-6488 Local Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 900018 CBL-Mariner Linux Security Update for glibc 2.28
- 902879 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (2550)
- 905959 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (2550-1)