---
title: "CVE-2017-18269\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-18269?format=md
keywords: index, follow
---

# CVE-2017-18269

Publication date 18 May 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2017-18269?format=md#impact-score)

Toggle side navigation

## Description

An SSE2-optimized memmove implementation for i386 in
sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library
(aka glibc or libc6) 2.21 through 2.27 does not correctly perform the
overlapping memory check if the source memory range spans the middle of the
address space, resulting in corrupt data being produced by the copy
operation. This may disclose information to context-dependent attackers, or
result in a denial of service, or, possibly, code execution.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2017-18269?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| eglibc | 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not affected |
| glibc | 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 16.04 LTS xenial | Fixed 2.23-0ubuntu11.2 |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2017-18269?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

introduced in glibc 2.21

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| glibc | * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=cd66c0e584c6d692bc8347b5e72723d02b8a8ada> * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=55ad82e45c313454de657931898e974a7a036cad> * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=71d339cb86dc58aa511dd1544dad2c77d075069c> * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=3f949b03473b4ca8b8e69a4e540511dfee39e493> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.8 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.8 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18269)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-18269)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-18269)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-18269)

### Related Ubuntu Security Notices (USN)

+ [USN-4416-1](https://usn.ubuntu.com/USN-4416-1)
+ GNU C Library vulnerabilities
+ 6 July 2020

### Other references

* <https://github.com/fingolfin/memmove-bug>
* <https://www.cve.org/CVERecord?id=CVE-2017-18269>
