ZeroHour

CVE-2018-6485

CVSS 3.0
9.8 critical
EPSS
5%p91
Published
()
Modified
Description

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.

Vendors
gnuredhatoraclenetapp
Products
glibc, virtualization host, enterprise linux desktop, enterprise linux server, enterprise linux workstation, communications session border controller, enterprise communications broker, cloud backup, data ontap edge, element software, element software management, steelstore cloud integrated storage
Weakness
CWE-190, CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.