CVE-2019-7309

Published: 03 February 2019

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Priority

Negligible

CVSS 3 base score: 5.5

Status

Package Release Status
eglibc
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Ignored

glibc
Launchpad, Ubuntu, Debian
Upstream
Released (2.30)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.31-0ubuntu9)
Ubuntu 18.04 LTS (Bionic Beaver) Ignored

Ubuntu 16.04 ESM (Xenial Xerus) Ignored

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Patches:
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=3f635fb43389b54f682fc9ed2acc0b2aaf4a923d (master)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=726a78867b3144e9b9da10197bcf59bde3d8b2a4 (2.29)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=9aaa083387fd1e19eb0bbd9f25444a5d5c91e210 (2.28)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=2ebadb6451eda1d518d70e26cf4ceeb0362e2456 (2.27)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=04e767b59b16befce93c6086362acbc1fae63f4e (2.26)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=2ad78b78d382c5e4bd805334617ac17f35ecff7e (2.25)
Upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=9146dc9d73aba08cf3fc2613a3f946c219dd2a52 (2.24)