VYPR
High severity8.1NVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026

CVE-2020-6096

CVE-2020-6096

Description

An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • GNU/Glibc2 versions
    cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*range: <=2.31
    • (no CPE)range: = 2.30.9000
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • GNU/glibcdescription

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.