CVE-2018-6485
—CVSS 3.0
9.8 critical
EPSS
5%p91
Published
()
Modified
Description
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
- Vendors
- gnuredhatoraclenetapp
- Products
- glibc, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux workstation, communications session border controller, enterprise communications broker, cloud backup, data ontap edge, element software, element software management, steelstore cloud integrated storage
- Weakness
- CWE-190, CWE-787
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.