VYPR
Unrated severityNVD Advisory· Published Nov 19, 2019· Updated Aug 5, 2024

CVE-2019-19126

CVE-2019-19126

Description

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

Affected products

6

Patches

1
9ea3686266dc

Generate ChangeLog.old/ChangeLog.20 for 2.31

https://github.com/bminor/glibcSiddhesh PoyarekarFeb 1, 2020via osv
1 file changed · +6542 0
  • ChangeLog.old/ChangeLog.20+6542 0 added

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.