ZeroHour

CVE-2018-11237

CVSS 3.1
7.8 high
EPSS
<1%p57
Published
()
Modified
Description

An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.

Vendors
gnuredhatoraclenetappcanonical
Products
glibc, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux workstation, communications session border controller, enterprise communications broker, data ontap edge, element software management, ubuntu linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.